MEDIUM
Sayontan Sinha
CVE published 2026-07-27
CVE-2026-66434
A Cross Site Scripting (XSS) vulnerability was found in the Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin, version <= 3.33. This issue allows contributors to inject malicious scripts, potentially leading to unauthorized actions or data exposure. Users of this plugin should be aware of the vulnerability and take steps to mitigate it.