Executive brief
The Document Gallery plugin for WordPress, which is used to manage and display document collections, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. By tricking a user into clicking a specially crafted link, an attacker could execute code in the user's browser, potentially leading to unauthorized actions, data theft, or website defacement. This issue affects all versions up to and including 5.1.0.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Dan Rossiter Document Gallery plugin for WordPress (versions <= 5.1.0). The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an unauthenticated attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim to interact with a malicious link or visit a crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized administrative actions, or redirection to malicious sites. The issue is addressed in version 5.1.1.
Affected products
- Dan Rossiter Document Gallery <= 5.1.0
Timeline
- 2026-03-21: other: Reported by Peter Thaleikis
- 2026-07-10: advisory: Patchstack advisory published
- 2026-07-13: disclosed: NVD publication date
- 5.1.1: patched: Vulnerability fixed in version 5.1.1