CVE-2026-104652 PUBLISHED

Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID

Assigner: WPScan
Reserved: 02.10.2026 Published: 07.10.2026 Updated: 07.10.2026

The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery.

Product Status

Vendor Unknown
Product Envira Gallery
Versions Default: unaffected
  • affected from 0 to 1.16.1 (excl.)

Credits

  • John Ryan Albon finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE