CVE-2026-104646
Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Shortcode Attributes
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing them into an inline script block, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of anyone viewing the post, including an administrator previewing a pending submission. No gallery ownership is required: any gallery that already exists on the site can be referenced.
| Vendor | unknown |
| Product | image photo gallery final tiles grid |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown image photo gallery final tiles grid
Be the first to know when new unknown vulnerabilities affecting unknown image photo gallery final tiles grid are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Image Photo Gallery Final Tiles Grid
0 < 3.6.14
References
Credits
Karthik Ramakrishnan WPScan