CVE-2026-104652
Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery.
| Vendor | unknown |
| Product | envira gallery |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown envira gallery
Be the first to know when new unknown vulnerabilities affecting unknown envira gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Envira Gallery
0 < 1.16.1
References
Credits
John Ryan Albon WPScan