Executive brief
The PhotoSwipe WordPress plugin, used for displaying image galleries, contains a security flaw that allows users with 'Author' permissions to inject malicious scripts into website pages. When a visitor or administrator views the affected image gallery and clicks a link, the hidden script executes in their browser. This could allow an attacker to hijack administrative sessions, steal sensitive information, or perform unauthorized actions on the website.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the PhotoSwipe WordPress plugin through version 4.1.1.1. The plugin fails to escape the 'title' attribute of author-supplied link markup before writing it to the DOM as a lightbox caption. While WordPress's standard post-content sanitization (wp_kses_post) allows the title attribute, the plugin's lightbox component subsequently renders this attribute using innerHTML. An authenticated attacker with Author-level privileges can inject a JavaScript payload (e.g., via an img tag with an onerror handler) that executes when any user, including an administrator, interacts with the lightbox. As of the advisory date, no fix is available.
Affected products
- Unknown PhotoSwipe <= 4.1.1.1
Timeline
- 2026-06-30: other: Vulnerability added to WPScan database
- 2026-07-07: disclosed: Publicly published by WPScan
- 2026-07-29: advisory: CVE published to NVD