Junglewise Threat Intelligence

CVE-2026-8867: WordPress Post Category Gallery Stored XSS in postcategorygallery shortcode

CVE-2026-8867 · Severity: medium · CVSS 6.4 · Published 2026-05-27

Vendors: Wordpress.

Executive brief

The Post Category Gallery plugin for WordPress, which allows users to display image galleries of post categories, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the sc_horcatbar() function. Specifically, user-supplied shortcode attributes such as 'total_width', 'color_scheme', and 'caption_font_size' are concatenated directly into HTML attribute values without proper neutralization. An authenticated attacker with contributor-level permissions or higher can exploit this by embedding malicious scripts within a shortcode. These scripts are then stored on the server and executed in the context of any user's browser who visits the compromised page. The vulnerability exists in all versions up to and including 1.0.0.

Affected products

  • WordPress Post Category Gallery Up to, and including, 1.0.0

Timeline

  • 2026-05-27: disclosed: Initial publication of the CVE record.
  • 2026-05-27: advisory: Wordfence published the vulnerability details.

References