VYPR
Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026

Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery

CVE-2026-12982

Description

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.