AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15386

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Meow Gallery WordPress plugin prior to version 5.5.2 is vulnerable due to improper escaping of attachment alt text, allowing users with Author roles or higher to inject JavaScript payloads. This can lead to cross-site scripting (XSS) attacks, potentially compromising the browsers of any visitors, including administrators, who view the affected galleries. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-15386
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%
WordPress Java

Original NVD Description

The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.