CVE-2025-26931: WordPress Tribulant Gallery Voting plugin <= 1.2.1 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Tribulant Gallery Voting gallery-voting allows Stored XSS.This issue affects Tribulant Gallery Voting: from n/a through <= 1.2.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26931?
CVE-2025-26931 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to stored XSS attacks.
How do I fix CVE-2025-26931?
To fix CVE-2025-26931, upgrade to a version of Tribulant Gallery Voting later than 1.2.1.
What software is affected by CVE-2025-26931?
CVE-2025-26931 affects Tribulant Gallery Voting versions from n/a up to and including 1.2.1.
What types of attacks can occur due to CVE-2025-26931?
CVE-2025-26931 can lead to malicious actions being performed on behalf of authenticated users, resulting in stored XSS vulnerabilities.
Who is vulnerable to CVE-2025-26931?
Any installation of the affected versions of Tribulant Gallery Voting or WordPress utilizing the plugin is vulnerable to CVE-2025-26931.