Review
SmugMug
CVE published 2026-10-11
CVE-2026-88826
The SmugMug Embed WordPress plugin through 3.13 has a vulnerability that allows unauthenticated users to store arbitrary web scripts, which can be executed when an administrator views the plugin's settings screen. This is due to the lack of authorization and CSRF checks on an AJAX action that stores gallery data, as well as the absence of sanitization or escaping of that data.