WordPress Gallery PhotoBlocks Plugin Cross Site Scripting vulnerability (CVE-2026-66448)
CVE number = CVE-2026-66448
This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.
While this vulnerability can be initiated by the role shown in “Required Privilege”, successful exploitation requires a privileged user to perform an action — such as clicking a malicious link, visiting a crafted page, or submitting a form.
Update to version 1.3.4 or later to resolve the vulnerability.
Patchstack users can turn on auto-update for vulnerable plugins only.

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.
