Sceawere
Vulnerability Detail
CVE-2026-39781UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Document Gallery Unauthenticated XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- Dan Rossiter
- Product
- Document Gallery
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:50.793Z",
"pubdate": "2026-10-06T09:17:50.793Z",
"executiveSummary": "The Document Gallery plugin for WordPress is vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) flaw in versions 5.1.1 and below.\nThis vulnerability allows unauthenticated attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session.\nThe flaw stems from improper neutralization of user-supplied input before rendering it in the browser, failing to implement adequate output encoding.\nSuccessful exploitation can lead to unauthorized actions performed on behalf of authenticated users, theft of session cookies, sensitive information disclosure, or the redirection of users to malicious external sites.\nGiven that the attack does not require authentication, it poses a significant risk to the integrity and confidentiality of the affected WordPress site's administrative and user sessions.\nImpacted systems are susceptible to drive-by attacks where an attacker crafts a malicious URL and lures a privileged user or site visitor into clicking the link.",
"technicalDetails": "The vulnerability resides in the way Document Gallery processes input parameters via HTTP GET or POST requests without sufficient sanitization or output escaping.\nThe root cause is the reflection of malicious user input directly into the HTML response document served by the web server to the client's browser.\nBy crafting a request containing a malicious payload—such as <script>alert('XSS')</script>—an attacker can bypass security controls because the application fails to validate the characters before the script is rendered.\nAttack flow: An unauthenticated attacker discovers an unsanitized input vector (e.g., a query string parameter) in a file path associated with the Document Gallery plugin. The attacker then constructs a malicious URL that embeds an obfuscated or direct JavaScript payload. Once this link is clicked by an authenticated user, such as an administrator, the browser executes the script under the security context of the origin domain.\nBecause the payload executes in the victim's session, the attacker can hijack session cookies, capture administrative keystrokes, modify site content, or extract CSRF tokens to perform unauthorized administrative operations.\nThe vulnerability is present in Document Gallery version 5.1.1 and all preceding versions that share the same code logic for parameter handling.\nExploitation requires no interaction from the developer or prior authentication; the only requirement is that a user with an active session accesses the attacker-crafted link.\nAs a Reflected XSS, the payload is typically delivered via malicious links disseminated through phishing, social engineering, or public forums. The browser treats the injected code as legitimate site content, successfully bypassing the Same-Origin Policy (SOP) constraints that would otherwise protect against cross-site data access."
}