CVE-2026-15386
Received Received - Intake

Stored XSS in Meow Gallery WordPress Plugin

Vulnerability report for CVE-2026-15386, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: WPScan

Description

The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
meow_gallery meow_gallery to 5.5.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the Meow Gallery WordPress plugin before version 5.5.2. It occurs because the plugin does not properly escape attachment alt text, allowing users with Author role or higher to inject malicious JavaScript payloads into galleries.

Detection Guidance

Check the installed version of the Meow Gallery plugin. If it is below 5.5.2, the system is vulnerable. Use WordPress admin panel or run: wp plugin list | grep meow-gallery in the WordPress directory.

Impact Analysis

Attackers with Author role or above can inject JavaScript that executes in the browsers of all visitors viewing a post with a vulnerable gallery. This includes administrators, potentially leading to session hijacking, data theft, or unauthorized actions on the site.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. It may result in non-compliance penalties if exploited.

Mitigation Strategies

Update the Meow Gallery plugin to version 5.5.2 or later immediately. If updating is not possible, disable the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15386. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart