CVE-2026-104653 PUBLISHED

Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions

Assigner: WPScan
Reserved: 02.10.2026 Published: 07.10.2026 Updated: 07.10.2026

The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page containing the affected gallery.

Product Status

Vendor Unknown
Product Envira Gallery
Versions Default: unaffected
  • affected from 0 to 1.16.1 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE