Sceawere
Vulnerability Detail
CVE-2026-107323UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Gallery PhotoBlocks Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Gallery PhotoBlocks
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-10T06:16:41.167Z",
"pubdate": "2026-10-10T06:16:41.167Z",
"executiveSummary": "The Gallery PhotoBlocks WordPress plugin versions prior to 1.3.6 contain a Stored Cross-Site Scripting (XSS) vulnerability.\nThis security flaw stems from improper input sanitization and output escaping of gallery settings within the plugin's administrative interface.\nThe vulnerability allows authenticated users with Contributor-level access or higher to inject malicious JavaScript payloads into gallery settings.\nWhen a victim, including users with higher administrative privileges, views a page containing the affected gallery, the injected script executes within their browser context.\nThis vulnerability poses a significant risk as it can lead to session hijacking, unauthorized administrative actions, or the deployment of further malicious client-side attacks.\nThe exploitation requirement is limited to an authenticated account with at least Contributor privileges, making it a viable target for malicious internal actors or compromised accounts.",
"technicalDetails": "The root cause of this vulnerability is the failure to properly sanitize input and escape output for specific gallery configuration settings within the Gallery PhotoBlocks plugin.\nThe plugin processes user-supplied data for display in HTML attributes without applying necessary security functions such as esc_attr(), which is required to prevent the injection of malicious code into HTML tag attributes.\nAn authenticated user with Contributor-level access—a role capable of editing posts and galleries—can manipulate gallery settings to inject arbitrary JavaScript sequences.\nBy crafting a payload specifically designed to break out of the HTML attribute context, an attacker can ensure the browser interprets the input as executable code.\nThe attack flow begins with the attacker modifying an existing gallery or creating a new one, where they inject the payload into a vulnerable setting field. Upon saving these settings, the malicious input is persisted in the WordPress database.\nWhen a page containing this gallery is rendered, the application retrieves the stored, unsanitized string and inserts it directly into the HTML markup.\nBecause the output is not escaped, the browser renders the attacker's payload as part of the document's active content rather than as plain text data.\nExecution occurs in the context of the victim's session. If an administrator views the page, the injected JavaScript executes with their session privileges, allowing the attacker to perform actions on behalf of the administrator, such as modifying plugin settings, changing user roles, or exfiltrating sensitive session tokens.\nThis vulnerability affects versions of Gallery PhotoBlocks before 1.3.6. The exposure is limited to authenticated users who possess sufficient permissions to access the plugin's configuration interfaces."
}