Executive brief
Photo Gallery by Supsystic is a WordPress plugin used to create and manage image galleries. A security vulnerability allows an attacker with administrative access to inject malicious scripts into the website's management interface. If another administrator views the affected area, the script could execute, potentially leading to unauthorized actions or the redirection of site visitors to malicious websites.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the Photo Gallery by Supsystic plugin for WordPress in versions up to and including 1.16.3. The flaw is due to improper neutralization of input during web page generation (CWE-79). An attacker with high privileges (Administrator) can inject malicious JavaScript payloads that execute in the context of another user's browser when they interact with the affected component. This requires user interaction from a victim. Successful exploitation could allow for session hijacking or unauthorized administrative actions. As of the advisory date, no official patch has been released.
Affected products
- Supsystic Photo Gallery by Supsystic <= 1.16.3
Timeline
- 2025-12-11: disclosed: Vulnerability reported by researcher Mrreee
- 2026-07-23: advisory: NVD and Patchstack published advisory details