Junglewise Threat Intelligence

CVE-2026-4559: Image Photo Gallery Final Tiles Grid stored XSS in delay shortcode

CVE-2026-4559 · Severity: medium · CVSS 6.4 · Published 2026-08-22

Executive brief

The Image Photo Gallery Final Tiles Grid WordPress plugin allows authenticated users to inject malicious scripts via the 'delay' shortcode attribute. When other users view pages containing these injected scripts, the malicious code executes in their browsers, potentially compromising their sessions, stealing data, or redirecting them to phishing sites. Only users with Contributor access or higher can inject these scripts.

Technical details

This is a Stored Cross-Site Scripting (XSS) vulnerability in the Image Photo Gallery Final Tiles Grid WordPress plugin, affecting versions up to and including 3.6.12. The vulnerability exists in the gallery-class.php file where the 'delay' shortcode attribute is processed with insufficient input sanitization and output escaping. Authenticated attackers with Contributor-level access and above can inject arbitrary JavaScript that persists in the WordPress database and executes whenever any user views the affected page. Exploitation requires the attacker to have WordPress user account privileges (Contributor role or higher), but once injected, the payload affects all site visitors without requiring further interaction.

Affected products

  • Image Photo Gallery Final Tiles Grid Gallery Lite up to and including 3.6.12

Timeline

  • 2026-08-22: disclosed
  • 2026-08-22: advisory: CVE-2026-4559 assigned

References