CVE-2026-65519: WordPress Photo Gallery plugin <= 2.7.7.29 - Cross Site Scripting (XSS) vulnerability
Published Jul 23, 2026
·Updated
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
Affected Software
1 affected component
wordpress/photo-gallery<=2.7.7.29
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Photo Gallery Pluginto a version that resolves this vulnerability.Fixed in 2.7.7.30
Event History
Jul 23, 2026
CVE Published
via MITRE·11:19 AM
Data Sourced
via MITRE·11:19 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65519?
The severity of CVE-2026-65519 is classified as medium, with a score of 6.5.
2
How do I fix CVE-2026-65519?
To fix CVE-2026-65519, update the WordPress Photo Gallery plugin to version 2.7.7.30 or later.
3
What is the impact of CVE-2026-65519?
CVE-2026-65519 allows for potential Cross Site Scripting (XSS) attacks, which can lead to unauthorized actions on behalf of users.
4
Which versions of the Photo Gallery plugin are affected by CVE-2026-65519?
CVE-2026-65519 affects the Photo Gallery plugin version 2.7.7.29 and earlier.
5
What type of vulnerability is CVE-2026-65519?
CVE-2026-65519 is categorized as a Cross Site Scripting (XSS) vulnerability.