CVE-2026-57695
HIGHWordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-57695. PoCs published by incogbyte.
AI-analyzed exploit summary Unauthenticated reflected XSS in Document Gallery WordPress plugin <= 5.1.0 via the `dg_generate_gallery` AJAX action. The vulnerability stems from unescaped user-supplied input in error messages, allowing arbitrary JavaScript execution in the context of a victim's browser.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.
Exploits (1)
Unauthenticated reflected XSS in Document Gallery WordPress plugin <= 5.1.0 via the `dg_generate_gallery` AJAX action. The vulnerability stems from unescaped user-supplied input in error messages, allowing arbitrary JavaScript execution in the context of a victim's browser.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L