๐Ÿ” CVE Alert

CVE-2026-15386

UNKNOWN 0.0

Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.

Vendor unknown
Product meow gallery
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown meow gallery

Be the first to know when new unknown vulnerabilities affecting unknown meow gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Meow Gallery
0 < 5.5.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/f76518ec-3abb-4b3c-b592-f5e24059304b/

Credits

Karthik Ramakrishnan WPScan