Junglewise Threat Intelligence

CVE-2026-57755: Misbah WP Mosaic Gallery , Advanced Gallery contributor XSS

CVE-2026-57755 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Executive brief

The Mosaic Gallery – Advanced Gallery plugin for WordPress is vulnerable to a security flaw that allows users with 'Contributor' level access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, these scripts could execute, potentially leading to unauthorized actions, website redirects, or the display of malicious advertisements. This risk is particularly relevant for sites that allow multiple users to contribute content.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the Mosaic Gallery – Advanced Gallery plugin for WordPress in versions up to and including 1.2.0. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with Contributor-level privileges can inject malicious JavaScript payloads into gallery settings or content. The vulnerability requires a privileged user (such as an administrator) to interact with the affected page for the script to execute in their browser context. As of the advisory date, no official patch has been released.

Affected products

  • Misbah WP Mosaic Gallery – Advanced Gallery <= 1.2.0

Timeline

  • 2026-02-06: disclosed: Reported by zaim
  • 2026-07-02: advisory: Published by Patchstack

References