CVE-2025-26581: WordPress Picture Gallery plugin <= 1.6.3 - CSRF to Stored XSS vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Picture Gallery picture-gallery allows Reflected XSS.This issue affects Picture Gallery: from n/a through <= 1.6.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26581?
The severity of CVE-2025-26581 is classified as critical due to its potential to allow reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-26581?
To fix CVE-2025-26581, upgrade Videowhisper Picture Gallery to version 1.6.3 or later.
Which versions of Picture Gallery are affected by CVE-2025-26581?
CVE-2025-26581 affects all versions of Videowhisper Picture Gallery up to and including 1.6.2.
What type of vulnerability is CVE-2025-26581?
CVE-2025-26581 is classified as an improper neutralization of input during web page generation, leading to reflected XSS.
Can CVE-2025-26581 affect WordPress installations?
Yes, CVE-2025-26581 also affects the WordPress Picture Gallery plugin up to version 1.6.2.