CVE-2026-102399: WordPress Photo Gallery by Supsystic plugin <= 1.21.0 - Cross Site Request Forgery (CSRF) vulnerability
Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/photo-gallery-by-supsysticto a version that resolves this vulnerability.Fixed in 1.21.1
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Sites using the Supsystic Photo Gallery by Supsystic WordPress plugin version 1.21.0 or earlier are affected. Exploitation can be initiated remotely and does not require the attacker to authenticate.
Does exploitation require interaction from a site user?
Yes. The CVSS vector indicates user interaction is required, meaning an attacker must cause a user to perform an action such as visiting or interacting with attacker-controlled content.
What is the potential impact of successful exploitation?
The vulnerability can affect integrity and availability, both rated Low in the supplied CVSS vector. No confidentiality impact is indicated.