CVE-2025-53240: WordPress WordPress Photo Gallery plugin <= 1.1.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamlabs WordPress Photo Gallery photo-gallery-portfolio allows Reflected XSS.This issue affects WordPress Photo Gallery: from n/a through <= 1.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53240?
CVE-2025-53240 is classified as a medium severity vulnerability due to its potential for causing reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-53240?
To fix CVE-2025-53240, update the WordPress Photo Gallery plugin to the latest version beyond 1.1.0.
What causes CVE-2025-53240?
CVE-2025-53240 is caused by improper neutralization of user input during web page generation in the WordPress Photo Gallery plugin.
Who is affected by CVE-2025-53240?
Users of the WordPress Photo Gallery plugin version 1.1.0 and below are affected by CVE-2025-53240.
What type of attacks can be launched with CVE-2025-53240?
CVE-2025-53240 can allow attackers to perform reflected cross-site scripting (XSS) attacks, potentially leading to user data exposure.