VYPR

Photo Swipe

by WordPress

CVEs (1)

  • CVE-2026-13605Jul 29, 2026
    risk 0.00cvss epss 0.00

    The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the…