Sceawere

Vulnerability Detail

CVE-2026-104409UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Final Tiles Grid

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
10h ago
Vendor
WP Chill
Product
Image Photo Gallery Final Tiles Grid
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T09:17:08.757Z",
  "pubdate": "2026-10-05T09:17:08.757Z",
  "executiveSummary": "A Stored Cross-Site Scripting (XSS) vulnerability exists in the WP Chill Image Photo Gallery Final Tiles Grid plugin for WordPress.\nThe vulnerability is classified under CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').\nAffected versions include all releases from n/a through 3.6.13.\nThe flaw enables an attacker to inject arbitrary malicious scripts into the web application, which are then persisted in the database.\nWhen an unsuspecting user, such as an administrator or a front-end visitor, views the affected component, the injected script executes within the context of their session.\nThis can lead to unauthorized actions, credential theft, session hijacking, or the redirection of users to malicious domains.\nExploitation does not necessarily require advanced network access, provided the attacker can interact with the input fields processed by the vulnerable plugin.\nThe impact is significant due to the potential for full account takeover if an administrator session is compromised.",
  "technicalDetails": "The vulnerability originates from the inadequate sanitization and validation of user-supplied data before it is persisted in the WordPress database and subsequently rendered in the browser.\nIn the context of the Image Photo Gallery Final Tiles Grid plugin, the application fails to properly neutralize meta-characters and script tags within input fields utilized for gallery configuration or metadata.\nBecause the plugin stores these malicious inputs without encoding them, it creates a Stored XSS condition where the payload resides permanently on the server side.\nThe attack flow begins when an attacker identifies an input vector within the plugin settings—typically fields intended for gallery titles, descriptions, or custom CSS/JS parameters—and submits a crafted payload containing script tags (e.g., <script>alert(document.cookie)</script>).\nOnce the input is saved, the application serves this content back to users visiting the gallery or viewing the admin dashboard.\nThe victim's web browser parses the stored input as legitimate code rather than plain text, triggering the execution of the attacker's JavaScript within the victim's security context.\nThis execution happens because the browser cannot distinguish between the developer-intended content and the injected malicious script.\nThe scope of the impact includes, but is not limited to, the exfiltration of session cookies, the performance of unauthorized administrative operations, or the modification of the DOM to display deceptive phishing content.\nThe vulnerability is present in versions up to 3.6.13. Successful exploitation is often dependent on the attacker having sufficient privileges to access the settings pages where vulnerable inputs exist, although depending on the implementation, some vectors may be accessible via front-end input forms if enabled.\nPost-exploitation, the attacker maintains control over the victim's interaction with the site, effectively bypassing authentication controls if they successfully hijack a session token."
}
CVE-2026-104409: Stored XSS in Final Tiles Grid (MEDIUM Severity, CVSS: 6.5) | Sceawere