PatchSiren

SmugMug CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review SmugMug CVE published 2026-10-11

CVE-2026-88826

The SmugMug Embed WordPress plugin through 3.13 has a vulnerability that allows unauthenticated users to store arbitrary web scripts, which can be executed when an administrator views the plugin's settings screen. This is due to the lack of authorization and CSRF checks on an AJAX action that stores gallery data, as well as the absence of sanitization or escaping of that data.