๐Ÿ” CVE Alert

CVE-2025-57974

UNKNOWN 0.0

WordPress TZ PlusGallery Plugin <= 1.5.5 - Cross Site Scripting (XSS) Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv TZ PlusGallery tz-plus-gallery allows Stored XSS.This issue affects TZ PlusGallery: from n/a through <= 1.5.5.

CWE CWE-79
Vendor tuyennv
Product tz plusgallery
Published Sep 22, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for tuyennv tz plusgallery

Be the first to know when new unknown vulnerabilities affecting tuyennv tz plusgallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

tuyennv / TZ PlusGallery
0 โ‰ค 1.5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/tz-plus-gallery/vulnerability/wordpress-tz-plusgallery-plugin-1-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve

Credits

Jieun Kim | Patchstack Bug Bounty Program