๐Ÿ” CVE Alert

CVE-2026-88826

UNKNOWN 0.0

SmugMug Embed <= 3.13 - Unauthenticated Stored XSS via saveSelectedAlbums

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when an administrator views the SmugMug Embed WordPress plugin through 3.13's settings screen.

Vendor unknown
Product smugmug embed
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown smugmug embed

Be the first to know when new unknown vulnerabilities affecting unknown smugmug embed are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / SmugMug Embed
0 โ‰ค 3.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6e8925b5-85a1-48e3-b744-df1c6fa24ed4/

Credits

Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan