NewsSecurity Vulnerabilities

WordPress Gallery PhotoBlocks Plugin Cross Site Scripting vulnerability (CVE-2026-66448)

CVE number = CVE-2026-66448

This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

While this vulnerability can be initiated by the role shown in “Required Privilege”, successful exploitation requires a privileged user to perform an action — such as clicking a malicious link, visiting a crafted page, or submitting a form.

Update to version 1.3.4 or later to resolve the vulnerability. 

Patchstack users can turn on auto-update for vulnerable plugins only.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.