CVE-2026-107323 PUBLISHED

Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS

Assigner: WPScan
Reserved: 07.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators.

Product Status

Vendor Unknown
Product Gallery PhotoBlocks
Versions Default: unaffected
  • affected from 1.3.5 to 1.3.6 (excl.)

Credits

  • Andy Urlep finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE