CVE-2026-13605
Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.
| Vendor | unknown |
| Product | photoswipe |
| Published | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown photoswipe
Be the first to know when new unknown vulnerabilities affecting unknown photoswipe are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / PhotoSwipe
0 โค 4.1.1.1
References
Credits
Pierre Rudloff WPScan