Junglewise Threat Intelligence

CVE-2026-5191: WordPress Tiled Gallery Carousel Without JetPack stored XSS

CVE-2026-5191 · Severity: medium · CVSS 5.4 · Published 2026-06-02

Vendors: Wordpress.

Executive brief

The Tiled Gallery Carousel Without JetPack plugin for WordPress, which provides image gallery and carousel functionality, contains a security flaw. An attacker with contributor-level access or higher can inject malicious scripts into image titles. These scripts will then execute in the browser of any visitor who views the affected gallery page, potentially leading to unauthorized actions or data theft.

Technical details

The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'data-image-title' parameter. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into this parameter. These scripts are stored on the server and execute in the context of a user's browser session whenever they access the page containing the malicious gallery. The vulnerability exists in all versions up to and including 3.1. The issue is tracked as CWE-79.

Affected products

  • WordPress Tiled Gallery Carousel Without JetPack Up to and including 3.1

Timeline

  • 2026-06-02: disclosed: Initial publication of the vulnerability details.
  • 2026-06-02: advisory: NVD and Wordfence published advisories.

References