CVE-2026-92422
Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.
| Vendor | unknown |
| Product | meow gallery |
| Published | Sep 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown meow gallery
Be the first to know when new unknown vulnerabilities affecting unknown meow gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Meow Gallery
0 < 5.5.5
References
Credits
JunHee CHO WPScan