Sceawere
Vulnerability Detail
CVE-2026-104646UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Final Tiles Grid
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Image Photo Gallery Final Tiles Grid
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing them into an inline script block, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of anyone viewing the post, including an administrator previewing a pending submission. No gallery ownership is required: any gallery that already exists on the site can be referenced.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-08T06:16:39.147Z",
"pubdate": "2026-10-08T06:16:39.147Z",
"executiveSummary": "The Image Photo Gallery Final Tiles Grid WordPress plugin, in versions prior to 3.6.14, contains a critical Stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from inadequate input sanitization of gallery configuration parameters passed through shortcodes.\nBy manipulating these configuration values, an authenticated user with contributor-level privileges or higher can inject malicious JavaScript payloads directly into inline script blocks rendered on the page. This vulnerability allows for the execution of unauthorized scripts in the browser session of any user viewing the affected post, including high-privileged administrators.\nBecause the plugin does not enforce ownership validation, an attacker can target any existing gallery on the site to facilitate the exploit. The primary risk involves session hijacking, unauthorized administrative actions, and potential site-wide compromise when an administrator previews or views content containing the malicious gallery shortcode. Exploitation requires authenticated access to the platform, but does not necessitate elevated privileges beyond contributor status.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure handling of shortcode attributes within the plugin's front-end rendering logic. When a gallery shortcode is parsed, the plugin extracts configuration parameters that define the behavior and aesthetic properties of the gallery. These parameters are subsequently reflected directly into inline script blocks intended for browser-side initialization of the gallery grid layout.\nThe vulnerability manifests because the plugin fails to perform rigorous input validation or contextual output encoding on these configuration values before embedding them into the JavaScript context. An attacker can craft a malicious shortcode by injecting standard XSS vectors—such as closing script tags or breaking out of string delimiters—to terminate the intended JavaScript block and execute arbitrary code.\nThe attack flow proceeds as follows: First, an attacker with contributor access identifies an existing gallery on the WordPress instance. Even without ownership of the gallery, the attacker utilizes the standard shortcode syntax to embed the gallery into a new or existing post. During this process, the attacker appends or modifies sensitive configuration attributes with a JavaScript payload. Upon saving or submitting the post for review, the payload is persisted in the WordPress database.\nWhen a victim, such as an administrator, views the post or accesses the preview functionality, the server renders the post content, including the malicious shortcode. The plugin processes the compromised configuration values and writes the untrusted input into an inline <script> tag. The victim's browser interprets the injected script, executing it within the security context of the site. This bypasses typical Same-Origin Policy (SOP) restrictions, allowing the attacker to perform actions on behalf of the victim.\nThis vulnerability is particularly severe due to the interaction with the administrator preview feature. If an attacker submits a post for review containing the malicious gallery, the unsuspecting administrator will trigger the payload upon opening the post to verify its content. This effectively turns the WordPress preview mechanism into a vector for administrative account compromise or site-wide configuration changes. Given that the plugin version prior to 3.6.14 lacks the necessary output escaping, the payload executes reliably in all modern browsers that do not employ strict Content Security Policy (CSP) headers to block inline script execution."
}