Executive brief
Gallery PhotoBlocks is a WordPress plugin used to create and manage image galleries on websites. A security flaw allows users with 'Contributor' level access to inject malicious scripts into the site. If an administrator or visitor views the affected content, these scripts could be used to redirect users to malicious sites, display unauthorized advertisements, or perform actions on behalf of the victim.
Technical details
The Gallery PhotoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to 1.3.3 due to insufficient input sanitization and output escaping. An attacker with 'Contributor' level privileges or higher can inject arbitrary web scripts into pages that execute whenever a user, including administrators, accesses the malicious content. The vulnerability requires user interaction (viewing the page) and is classified under CWE-79. The issue has been addressed in version 1.3.4.
Affected products
- WP Chill Gallery PhotoBlocks <= 1.3.3
Timeline
- 2026-02-11: other: Reported by Muhammad Sharief
- 2026-07-27: advisory: Published by Patchstack and NVD
- 2026-07-27: patched: Version 1.3.4 released to address the vulnerability