Stored Cross-Site Scripting Vulnerability in Tiled Gallery Carousel Without JetPack Plugin for WordPress
CVE-2026-5191
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 June 2026
What is CVE-2026-5191?
The Tiled Gallery Carousel Without JetPack plugin for WordPress has a vulnerability that allows stored cross-site scripting (XSS) through the 'data-image-title' parameter. This issue arises from inadequate input sanitization and output escaping, enabling authenticated users with contributor-level access or higher to insert malicious web scripts into pages. Consequently, these scripts execute whenever a user visits the compromised page, posing serious security risks for both the website and its users.
Affected Version(s)
Tiled Gallery Carousel Without JetPack 0 <= 3.1