Junglewise Threat Intelligence

CVE-2026-5361: Envira Gallery Lite Stored XSS in REST API

CVE-2026-5361 · Severity: medium · CVSS 6.4 · Published 2026-05-14

Executive brief

Envira Gallery Lite is a popular WordPress plugin used to create and manage image galleries. A security flaw allows users with 'Author' level permissions or higher to inject malicious scripts into gallery pages. When other users or administrators visit these pages, the scripts execute automatically, which could lead to unauthorized actions or data theft.

Technical details

The Envira Gallery Lite plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization in the update_gallery_data() function and improper output escaping in the gallery_init() function. Specifically, the sanitize_config_values() function fails to sanitize the 'arrows' parameter. When this parameter is subsequently rendered in an inline JavaScript configuration, the plugin uses esc_attr(), which is insufficient for JavaScript contexts and allows for expression injection. Authenticated attackers with Author-level privileges can exploit this via the REST API to inject malicious scripts. A patch appears to be available in versions following 1.12.4.

Affected products

  • Envira Gallery Envira Gallery Lite up to and including 1.12.4

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References