{"id":"CVE-2026-107323","title":"The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that e…","summary":"The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that e…","severity":"none","published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T06:16:41.167","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107323","references":[{"url":"https://wpscan.com/vulnerability/19a8c2db-fb31-4203-83d6-139b35c93a80/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T06:24:42.865Z","slug":"CVE-2026-107323","body":"## Overview\n\nThe Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}