CVE-2025-60104: WordPress Gallery Custom Links Plugin <= 2.2.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery Custom Links allows Stored XSS. This issue affects Gallery Custom Links: from n/a through 2.2.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery Custom Links gallery-custom-links allows Stored XSS.This issue affects Gallery Custom Links: from n/a through <= 2.2.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60104?
CVE-2025-60104 has a high severity rating due to its potential for allowing stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-60104?
To fix CVE-2025-60104, update the Jordy Meow Gallery Custom Links plugin to version 2.2.6 or later.
What versions are affected by CVE-2025-60104?
CVE-2025-60104 affects Jordy Meow Gallery Custom Links and WordPress Gallery Custom Links Plugin versions up to and including 2.2.5.
What is the impact of CVE-2025-60104?
The impact of CVE-2025-60104 includes the potential for attackers to execute arbitrary scripts in users' browsers.
Who is impacted by CVE-2025-60104?
Users of the Jordy Meow Gallery Custom Links plugin and WordPress Gallery Custom Links Plugin are impacted by CVE-2025-60104.