CVE-2026-97290: WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.36 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/photonic-gallery-lightbox-for-flickr-smugmug-othersto a version that resolves this vulnerability.Fixed in 3.37
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
What security impact can successful exploitation have?
The supplied vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. The issue is classified as cross-site scripting.
Which installations are known to be affected?
Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin versions 3.36 and earlier are identified as affected.