Stored Cross-Site Scripting in Envira Gallery Plugin for WordPress
CVE-2026-3423
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-3423?
The Envira Gallery plugin for WordPress is susceptible to a Stored Cross-Site Scripting issue. This flaw arises from inadequate input sanitization and output escaping, specifically in the 'description' configuration field. Authenticated attackers with Author-level access can exploit this vulnerability to inject malicious web scripts. These scripts will execute whenever a user accesses a page displaying the gallery with an enabled description, posing serious risks to site security and user data.
Affected Version(s)
Envira Gallery β Image Photo Gallery, Albums, Video Gallery, Slideshows & More 0 <= 1.12.4