Executive brief
Zielke Design Project Gallery is a WordPress plugin used to display photo galleries and project portfolios on websites. The plugin contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. An attacker could trick a website visitor into clicking a malicious link, potentially stealing their login credentials or session data, or redirecting them to fraudulent sites.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the Zielke Design Project Gallery WordPress plugin versions up to 2.5.0. The plugin fails to properly sanitize user-supplied input when generating web pages, allowing attackers to inject arbitrary JavaScript code. This is an unauthenticated reflected XSS that requires a victim to click on a crafted link or visit an attacker-controlled page. Successful exploitation allows attackers to execute arbitrary JavaScript in the context of a visitor's browser, potentially enabling credential theft, session hijacking, or malware distribution. No official patch is currently available; users should monitor for updates or use WordPress security plugins to apply mitigation rules.
Affected products
- Terry Zielke Zielke Design Project Gallery <= 2.5.0
Timeline
- 2025-03-19: disclosed
- 2025-12-31: advisory