Executive brief
The Fancy Image Show plugin for WordPress, which is used to display image galleries, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or administrators visit these affected pages, the hidden scripts will execute in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'fancy-img-show' shortcode. The vulnerability exists in all versions up to and including 9.1 and is caused by insufficient input sanitization and output escaping on user-supplied attributes within the shortcode. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into a post or page. These scripts will then execute in the context of any user's browser who views the compromised page. The CVSS score of 6.4 reflects the requirement for basic authentication and the potential for cross-site impact.
Affected products
- Fancy Image Show Fancy Image Show Up to, and including, 9.1
Timeline
- 2026-05-12: disclosed: Initial publication of the CVE record.
- 2026-05-12: advisory: Wordfence published the vulnerability details.
References
- https://plugins.trac.wordpress.org/browser/fancy-image-show/tags/9.1/fancy-image-show.php
- https://plugins.trac.wordpress.org/browser/fancy-image-show/tags/9.1/fancy-image-show.php
- https://plugins.trac.wordpress.org/browser/fancy-image-show/trunk/fancy-image-show.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/131d07ad-4e87-4137-a5df-2b74db1e9ae8?source=cve