PatchSiren

Gallery PhotoBlocks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Gallery PhotoBlocks CVE published 2026-10-10

CVE-2026-107323

The Gallery PhotoBlocks WordPress plugin before 1.3.6 does not sanitize and escape one of its gallery settings before outputting it into an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of anyone who views a page containing the gallery, including administrators. This stored XSS vulnerability can lead to malicious JavaScript executio [truncated]