CVE-2025-27326: WordPress Video Gallery Block plugin <= 1.1.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gallery Block – Display your videos as a gallery in a professional way allows Stored XSS. This issue affects Video Gallery Block – Display your videos as a gallery in a professional way: from n/a through 1.1.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gallery Block video-gallery-block allows Stored XSS.This issue affects Video Gallery Block: from n/a through <= 1.1.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27326?
CVE-2025-27326 is classified as a stored cross-site scripting (XSS) vulnerability, which can lead to significant security risks.
How do I fix CVE-2025-27326?
To resolve CVE-2025-27326, update the bPlugins Video Gallery Block to version 1.1.1 or later.
What versions are affected by CVE-2025-27326?
CVE-2025-27326 affects bPlugins Video Gallery Block version 1.1.0 and earlier.
What kind of attack does CVE-2025-27326 allow?
CVE-2025-27326 allows for stored cross-site scripting (XSS) attacks, potentially enabling attackers to inject malicious scripts.
Who is impacted by CVE-2025-27326?
Users of the bPlugins Video Gallery Block and WordPress Video Gallery Block up to version 1.1.0 are impacted by CVE-2025-27326.