Junglewise Threat Intelligence

CVE-2026-10104: nikhilgadhiya Product Video Gallery for Woocommerce Stored XSS

CVE-2026-10104 · Severity: medium · CVSS 4.4 · Published 2026-07-02

Executive brief

The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to a security flaw that allows high-level users, such as shop managers, to inject malicious scripts into product pages. This occurs because the plugin does not properly clean data provided in the custom thumbnail settings. If exploited, these scripts will run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'custom_thumbnail' parameter. An authenticated attacker with high-level privileges (Shop Manager or higher) can inject arbitrary JavaScript into the database. This script is then executed in the context of a user's browser session whenever they access the page where the malicious thumbnail data is rendered. The vulnerability is present in all versions up to and including 1.5.1.8. A patch has been released in subsequent versions to address the sanitization failure.

Affected products

  • nikhilgadhiya Product Video Gallery for Woocommerce up to, and including, 1.5.1.8

Timeline

  • 2026-07-02: disclosed: CVE published by Wordfence/NVD

References