VYPR

SmugMug Embed

by WordPress

CVEs (1)

  • CVE-2026-88826Oct 11, 2026
    risk 0.00cvss —epss —

    The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when…