Deze pagina is nog niet vertaald naar uw taal. We werken eraan — de inhoud wordt voorlopig in het Engels weergegeven.
💡 Keep dependencies up to date — most exploits target known, patchable vulnerabilities.
CVE-2026-5361: XSS in Envira Gallery Lite WordPress Plugin
Platform
wordpress
Component
envira-gallery-lite
Opgelost in
1.12.5
CVE-2026-5361 describes a Stored Cross-Site Scripting (XSS) vulnerability affecting the Envira Gallery Lite plugin for WordPress. This vulnerability allows attackers to inject malicious scripts into the gallery, potentially leading to unauthorized code execution within a user's browser. The vulnerability impacts versions 1.0.0 through 1.12.4 and is resolved in version 1.12.5.
Detecteer deze CVE in je project
Upload je dependency-bestand en kom direct te weten of deze en andere CVEs jou raken.
Impact en Aanvalsscenarioswordt vertaald…
An attacker exploiting this XSS vulnerability could inject arbitrary JavaScript code into the Envira Gallery Lite plugin. This code could then be executed in the browsers of users viewing the affected gallery. The impact ranges from simple defacement and redirection to more severe consequences like stealing session cookies, phishing attacks, or even gaining control of the user's WordPress account. The REST API endpoint is a common target for such attacks, and successful exploitation could impact a significant number of WordPress sites using the Envira Gallery Lite plugin. The lack of proper sanitization of the 'arrows' parameter is the root cause, allowing attackers to bypass security measures.
Uitbuitingscontextwordt vertaald…
CVE-2026-5361 was published on 2026-05-14. Severity is rated as Medium (CVSS 6.4). No public exploits or active campaigns have been reported as of this writing. The vulnerability is not currently listed on KEV or EPSS, indicating a low to medium probability of exploitation. Refer to the official Envira Gallery Lite advisory for further details.
Dreigingsinformatie
Exploit Status
CISA SSVC
CVSS-vector
Wat betekenen deze metrics?
- Attack Vector
- Netwerk — op afstand uitbuitbaar via internet. Geen fysieke of lokale toegang vereist.
- Attack Complexity
- Laag — geen speciale voorwaarden vereist. Betrouwbaar uitbuitbaar.
- Privileges Required
- Laag — elk geldig gebruikersaccount is voldoende.
- User Interaction
- Geen — automatische en stille aanval. Slachtoffer doet niets.
- Scope
- Gewijzigd — aanval kan voorbij het kwetsbare component uitbreiden naar andere systemen.
- Confidentiality
- Laag — gedeeltelijke toegang tot enkele gegevens.
- Integrity
- Laag — aanvaller kan enkele gegevens met beperkte omvang aanpassen.
- Availability
- Geen — geen beschikbaarheidsimpact.
Getroffen Software
Zwakheidsclassificatie (CWE)
Tijdlijn
- Gereserveerd
- Gepubliceerd
- Gewijzigd
Mitigatie en Workaroundswordt vertaald…
The primary mitigation for CVE-2026-5361 is to upgrade the Envira Gallery Lite plugin to version 1.12.5 or later. If immediate upgrading is not possible due to compatibility issues or testing requirements, consider implementing a Web Application Firewall (WAF) rule to block requests to the vulnerable REST API endpoint with suspicious parameters. Carefully review any custom code interacting with the gallery data to ensure proper input sanitization and output escaping. Monitor WordPress logs for unusual activity or attempts to access the REST API with potentially malicious payloads.
Hoe te verhelpen
Update naar versie 1.12.5, of een nieuwere gepatchte versie
Veelgestelde vragenwordt vertaald…
What is CVE-2026-5361 — XSS in Envira Gallery Lite?
CVE-2026-5361 is a Stored Cross-Site Scripting (XSS) vulnerability in the Envira Gallery Lite WordPress plugin, allowing attackers to inject malicious scripts via the REST API.
Am I affected by CVE-2026-5361 in Envira Gallery Lite?
You are affected if you are using Envira Gallery Lite versions 1.0.0 through 1.12.4. Check your plugin version and update if necessary.
How do I fix CVE-2026-5361 in Envira Gallery Lite?
Upgrade the Envira Gallery Lite plugin to version 1.12.5 or later. Consider WAF rules as a temporary mitigation if upgrading is not immediately possible.
Is CVE-2026-5361 being actively exploited?
As of now, there are no reports of active exploitation or public exploits for CVE-2026-5361, but vigilance is still advised.
Where can I find the official Envira Gallery Lite advisory for CVE-2026-5361?
Refer to the official Envira Gallery Lite website and WordPress plugin repository for the latest advisory and update information.
Is jouw project getroffen?
Upload je dependency-bestand en kom direct te weten of deze en andere CVEs jou raken.
Detecteer deze CVE in je project
Upload je dependency-bestand en kom direct te weten of deze en andere CVEs jou raken.
Scan nu uw WordPress project — geen account
Upload een manifest (composer.lock, package-lock.json, WordPress pluginlijst…) of plak uw componentenlijst. U ontvangt direct een kwetsbaarheidsrapport. Een bestand uploaden is slechts het begin: met een account krijgt u continue monitoring, Slack/e-mail alerts, multi-project en white-label rapporten.
Sleep uw afhankelijkheidsbestand hierheen
composer.lock, package-lock.json, requirements.txt, Gemfile.lock, pubspec.lock, Dockerfile...