CVE-2026-104646: CWE-79 Cross-Site Scripting (XSS) in Image Photo Gallery Final Tiles Grid
Description
The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.14 does not sanitise several gallery configuration values that can be overridden through its gallery shortcode before printing them into an inline script block, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of anyone viewing the post, including an administrator previewing a pending submission. No gallery ownership is required: any gallery that already exists on the site can be referenced.
CVSS v3.1
Score 6.8medium
Affected software
Image Photo Gallery Final Tiles Grid
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104646 is a cross-site scripting (CWE-79) vulnerability in the Image Photo Gallery Final Tiles Grid WordPress plugin versions prior to 3.6.14. The vulnerability occurs because the plugin does not sanitize certain gallery configuration values that can be overridden through its shortcode. This allows users with contributor-level privileges or higher to inject malicious JavaScript into an inline script block. The injected script executes in the session context of any user viewing the post, including administrators previewing pending submissions. Exploitation does not require ownership of the referenced gallery, only that the gallery exists on the site.
Potential Impact
Successful exploitation allows an attacker with contributor-level access or above to execute arbitrary JavaScript in the browsers of users viewing the affected post. This can lead to session hijacking, privilege escalation, or other malicious actions within the context of the vulnerable WordPress site. The vulnerability affects all users who view the compromised post, including administrators, increasing the risk of site compromise.
Mitigation Recommendations
A fix is available in version 3.6.14 of the Image Photo Gallery Final Tiles Grid plugin. Users should upgrade to version 3.6.14 or later to remediate this vulnerability. Until then, restrict contributor-level access to trusted users and avoid referencing existing galleries in shortcodes from untrusted contributors. Patch status is confirmed by the versioning information indicating the vulnerability is fixed in 3.6.14.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-10-02T05:40:36.829Z
- State
- PUBLISHED
Threat ID: 6ac735da2cdf04f656f03ea0
Added to database: 10/08/2026, 06:19:06 UTC
Last enriched: 10/08/2026, 06:34:19 UTC
Last updated: 10/08/2026, 18:48:43 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.