CVE-2025-57947: WordPress Photo Gallery by Ays Plugin <= 6.3.8 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Photo Gallery by Ays allows DOM-Based XSS. This issue affects Photo Gallery by Ays: from n/a through 6.3.6.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Photo Gallery by Ays gallery-photo-gallery allows DOM-Based XSS.This issue affects Photo Gallery by Ays: from n/a through <= 6.3.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57947?
CVE-2025-57947 has a medium severity rating due to its potential for enabling Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-57947?
To fix CVE-2025-57947, update Ays Photo Gallery to version 6.3.7 or later to eliminate the vulnerability.
What versions of Ays Photo Gallery are affected by CVE-2025-57947?
CVE-2025-57947 affects Ays Photo Gallery versions up to and including 6.3.6.
What type of vulnerability is CVE-2025-57947?
CVE-2025-57947 is a Cross-site Scripting (XSS) vulnerability caused by improper input neutralization.
Can CVE-2025-57947 be exploited remotely?
Yes, CVE-2025-57947 can be exploited remotely, allowing attackers to execute malicious scripts in the context of the user's browser.