VYPR

Tiled Gallery Carousel Without JetPack

by WordPress

CVEs (1)

  • CVE-2026-5191MedJun 2, 2026
    risk 0.35cvss 5.4epss

    The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for…