๐Ÿ” CVE Alert

CVE-2026-104653

UNKNOWN 0.0

Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page containing the affected gallery.

Vendor unknown
Product envira gallery
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown envira gallery

Be the first to know when new unknown vulnerabilities affecting unknown envira gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Envira Gallery
0 < 1.16.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6fba4124-edb1-4363-8ad9-4aa77e1b3890/

Credits

Karthik Ramakrishnan WPScan