Junglewise Threat Intelligence

CVE-2026-84781: Gallery PhotoBlocks contributor cross-site scripting vulnerability

CVE-2026-84781 · Severity: medium · CVSS 6.5 · Published 2026-09-02

Vendors: WP Chill.

Executive brief

Gallery PhotoBlocks is a popular WordPress plugin for creating image galleries. A contributor-level user can inject malicious scripts into gallery content that affects visitors to the site. An attacker with contributor privileges could steal visitor data, hijack accounts, or deface the site.

Technical details

A cross-site scripting (XSS) vulnerability exists in Gallery PhotoBlocks plugin versions up to 1.3.4, allowing an attacker with contributor-level privileges to inject malicious JavaScript into gallery content. The vulnerability requires user interaction (such as a privileged user clicking a malicious link or visiting a crafted page) to be successfully exploited. An attacker can execute arbitrary scripts in the context of the website, potentially stealing session cookies, hijacking visitor accounts, or performing unauthorized actions. The vulnerability is patched in version 1.3.5 and later.

Affected products

  • WP Chill Gallery PhotoBlocks <= 1.3.4

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in version 1.3.5

References

Related threats