The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 has a stored XSS vulnerability via gallery shortcode attributes. Users with contributor-level access can inject JavaScript that executes in the session of anyone viewing the post. This vulnerability allows for JavaScript injection and execution in user sessions, potentially leading to administrator compromise and exposure of sensitive [truncated]
ReviewImage Photo Gallery Final Tiles GridCVE published 2026-10-08
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 has an authorization issue allowing contributors and above to clone, modify, and reorder galleries and images belonging to other users and update metadata on arbitrary posts. This vulnerability allows unauthorized actions on galleries and images, potentially leading to unintended modifications and exposure of sensitive information. De [truncated]