Photographers galleries <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
mediumThe Photographers galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes (`w`, `h`, `raw_css`, `look`, etc.) in all versions up to, and including, 1.1.8. This is due to the plugin not properly sanitizing user input or escaping output when inserting these values int...
- CVSS:
- 6.4
- Affected:
- up to 1.1.8
- Fix:
- No patched version reported
- Disclosed:
- Oct 21, 2025