Executive brief
A vulnerability exists in the Photo Gallery plugin for WordPress, which is used to display image and video galleries on websites. An attacker with Author-level permissions could inject malicious scripts into the site, potentially leading to unauthorized redirects, unwanted advertisements, or the theft of session information from other users. This could damage a site's reputation or lead to further compromise if a site administrator interacts with the malicious content.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the GT3 Themes Photo Gallery plugin (gt3-photo-video-gallery) for WordPress due to improper neutralization of input during web page generation (CWE-79). An attacker with Author-level privileges can inject malicious scripts that execute in the context of a victim's browser, typically requiring a more privileged user (like an Administrator) to view the affected page. The vulnerability is present in versions up to and including 2.7.7.29 and was addressed in version 2.7.7.30.
Affected products
- GT3 Themes Photo Gallery (gt3-photo-video-gallery) <= 2.7.7.29
Timeline
- 2026-07-13: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-23: advisory: NVD and Patchstack advisories published
- 2026-07-23: patched: Fixed in version 2.7.7.30