๐Ÿ” CVE Alert

CVE-2026-13605

UNKNOWN 0.0

Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.

Vendor unknown
Product photoswipe
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for unknown photoswipe

Be the first to know when new unknown vulnerabilities affecting unknown photoswipe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / PhotoSwipe
0 โ‰ค 4.1.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7ec73098-99eb-48cb-8ff6-a05110691117/

Credits

Pierre Rudloff WPScan