PatchSiren

Image Photo Gallery Final Tiles Grid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Image Photo Gallery Final Tiles Grid CVE published 2026-10-08

CVE-2026-104646

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 has a stored XSS vulnerability via gallery shortcode attributes. Users with contributor-level access can inject JavaScript that executes in the session of anyone viewing the post. This vulnerability allows for JavaScript injection and execution in user sessions, potentially leading to administrator compromise and exposure of sensitive [truncated]

Review Image Photo Gallery Final Tiles Grid CVE published 2026-10-08

CVE-2026-104645

The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 has an authorization issue allowing contributors and above to clone, modify, and reorder galleries and images belonging to other users and update metadata on arbitrary posts. This vulnerability allows unauthorized actions on galleries and images, potentially leading to unintended modifications and exposure of sensitive information. De [truncated]