---
id: CVE-2026-104653
title: >-
  The Envira Gallery  WordPress plugin before 1.16.1 does not sanitise or escape
  user-supplied gallery display configuration values before storing them and
  outputting them in an image tag attribute, allowing users with the Author role
  and …
summary: >-
  The Envira Gallery  WordPress plugin before 1.16.1 does not sanitise or escape
  user-supplied gallery display configuration values before storing them and
  outputting them in an image tag attribute, allowing users with the Author role
  and …
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Envira Gallery
affected:
  - envira_gallery < 1.16.1
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T10:17:27.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104653'
references:
  - url: 'https://wpscan.com/vulnerability/6fba4124-edb1-4363-8ad9-4aa77e1b3890/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-07T09:55:09.264672Z'
ingestedAt: '2026-10-07T08:20:03.939Z'
---

## Overview

The Envira Gallery  WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page containing the affected gallery.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
