CVE-2026-104652: Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID
The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability and who is affected by the injected script?
A user with the WordPress Author role or any higher-privileged role can exploit it. The stored script runs when any visitor views a page that embeds the affected gallery, including administrators.
What input is used to deliver the stored XSS payload?
The attacker injects script through a gallery image item identifier. The plugin outputs that identifier into an image tag attribute without sanitising and escaping it.
Which plugin versions are affected?
Envira Gallery versions before 1.16.1 are affected. Version 1.16.1 is the first version identified as not affected by the stated issue.