← Back to CVE search

CVE-2026-12982

Document Gallery

Description

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.

CVSS 6.1EPSS 0.16199999999999998%Risk 0.62
View source
Published
2026-07-27 07:16:24
Affected versions
<5.1.1
Type
Web application
Last modified
2026-07-27 20:33:01
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N