CVE-2026-15386
Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.
| Vendor | unknown |
| Product | meow gallery |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown meow gallery
Be the first to know when new unknown vulnerabilities affecting unknown meow gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Meow Gallery
0 < 5.5.2
References
Credits
Karthik Ramakrishnan WPScan