Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026
Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
CVE-2026-12982
Description
The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.
Affected products
1- Range: <5.1.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/a3c279ce-5db1-4331-ad74-4eef49619737/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.