Junglewise Threat Intelligence

CVE-2021-47951: videowhisper Picture Gallery stored XSS in Access Control settings

CVE-2021-47951 · Severity: medium · CVSS 6.4 · Published 2026-05-10

Vendors: VideoWhisper.

Executive brief

The Picture Gallery plugin for WordPress, which allows users to manage and upload images, contains a security flaw in its access control settings. An attacker with basic account access can inject malicious scripts into the plugin's configuration. If triggered, these scripts could allow the attacker to steal user session information or hijack administrative accounts, potentially compromising the entire website.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the WordPress Picture Gallery plugin version 1.4.2. The flaw is located in the 'Edit Content URL' input field within the Access Control tab of the plugin's options. An authenticated attacker can submit a malicious JavaScript payload that is stored in the database without proper sanitization. This script executes in the context of any user (including administrators) who accesses the affected settings page, potentially leading to session hijacking, credential theft, or unauthorized administrative actions. A proof-of-concept exploit using an alert payload has been publicly disclosed.

Affected products

  • videowhisper Picture Gallery 1.4.2

Timeline

  • 2021-08-06: disclosed: Vulnerability discovered and exploit authored
  • 2021-08-10: other: Exploit published on Exploit-DB
  • 2026-05-10: advisory: CVE published/updated via VulnCheck

References

Related threats