CVE-2026-92422: Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route
Published Sep 20, 2026
·Updated
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.
Affected Software
1 affected component
Meow Gallery Meow Gallery WordPress plugin<5.5.5
Event History
Sep 20, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which plugin versions are affected?
Meow Gallery versions before 5.5.5 are affected.
2
Does exploitation require a WordPress account or other authentication?
No. The vulnerable REST route is publicly reachable, so an unauthenticated user can invoke it.
3
What could an attacker obtain through this issue?
An attacker can execute registered WordPress shortcodes through the affected route and may disclose non-public gallery content.
4
What is the available remediation?
Upgrade Meow Gallery to version 5.5.5 or later.