Junglewise Threat Intelligence

CVE-2025-23705: Zielke Design Project Gallery reflected XSS

CVE-2025-23705 · Severity: high · CVSS 7.1 · Published 2025-12-31

Executive brief

Zielke Design Project Gallery is a WordPress plugin used to display photo galleries and project portfolios on websites. The plugin contains a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. An attacker could trick a website visitor into clicking a malicious link, potentially stealing their login credentials or session data, or redirecting them to fraudulent sites.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw in the Zielke Design Project Gallery WordPress plugin versions up to 2.5.0. The plugin fails to properly sanitize user-supplied input when generating web pages, allowing attackers to inject arbitrary JavaScript code. This is an unauthenticated reflected XSS that requires a victim to click on a crafted link or visit an attacker-controlled page. Successful exploitation allows attackers to execute arbitrary JavaScript in the context of a visitor's browser, potentially enabling credential theft, session hijacking, or malware distribution. No official patch is currently available; users should monitor for updates or use WordPress security plugins to apply mitigation rules.

Affected products

  • Terry Zielke Zielke Design Project Gallery <= 2.5.0

Timeline

  • 2025-03-19: disclosed
  • 2025-12-31: advisory

References