CVE-2026-88826
SmugMug Embed <= 3.13 - Unauthenticated Stored XSS via saveSelectedAlbums
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when an administrator views the SmugMug Embed WordPress plugin through 3.13's settings screen.
| Vendor | unknown |
| Product | smugmug embed |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown smugmug embed
Be the first to know when new unknown vulnerabilities affecting unknown smugmug embed are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / SmugMug Embed
0 โค 3.13
References
Credits
Enrico Marcolini - Claudio Marchesini - Dottor Marc WPScan