CVE-2026-104409: WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.13 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Image Photo Gallery Final Tiles Grid pluginto a version that resolves this vulnerability.Fixed in 3.6.14
Event History
Frequently Asked Questions
Which deployments are affected?
The affected product is WP Chill Image Photo Gallery Final Tiles Grid, with versions through 3.6.13 identified as affected. The supplied data does not identify a fixed version.
What access does an attacker need to exploit this issue?
The CVSS vector indicates network reachability, low attack complexity, low privileges required, and user interaction required. This means an attacker must have some authenticated privilege and needs a user to interact with the injected content.
What is the likely impact of successful exploitation?
This is stored cross-site scripting, so malicious input can persist and execute in another user's browser when the affected page is viewed or otherwise interacted with. The provided vector rates confidentiality, integrity, and availability impact as low, with scope changed.