Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-88826
CVE-2026-88826
Description
The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when an administrator views the SmugMug Embed WordPress plugin through 3.13's settings screen.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=3.13
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.