[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fp05ue0qFQvDEz5hOdh1mt48ay75xhNucMrzp2AIh09w":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":28,"research_verified":29,"research_rounds_completed":30,"research_plan":31,"research_summary":9,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":32,"research_started_at":33,"research_completed_at":34,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":29,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":29,"source_links":35},"CVE-2026-57695","document-gallery-unauthenticated-stored-cross-site-scripting","Document Gallery \u003C= 5.1.0 - Unauthenticated Stored Cross-Site Scripting","The Document Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","document-gallery",null,"\u003C=5.1.0","5.1.1","high",7.2,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2026-07-10 00:00:00","2026-07-14 19:16:59",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F5a081cbd-5cd9-4740-a720-0e4d8904fc4b?source=api-prod",5,[22,23,24,25,26,27],"CHANGELOG.md","README.txt","document-gallery.php","package.json","src\u002Finc\u002Fclass-gallery-sanitization.php","src\u002Finc\u002Fclass-gallery.php","researched",false,3,"# Exploitation Research Plan - CVE-2026-57695\n\n## 1. Vulnerability Summary\n**CVE-2026-57695** is a stored Cross-Site Scripting (XSS) vulnerability in the **Document Gallery** plugin for WordPress (versions \u003C= 5.1.0). The vulnerability arises from two critical failures:\n1.  **Broken Access Control on Settings Update:** The plugin's administrative initialization logic (likely in `src\u002Fadmin\u002Fclass-admin.php` or `src\u002Finc\u002Fclass-setup.php`) allows unauthenticated users to trigger an update of the plugin's global options (`document_gallery`).\n2.  **Insufficient Output Escaping:** Several gallery settings, such as `mime_types`, `descriptions`, or custom CSS attributes, are stored in the database and subsequently rendered in the HTML output of the `[dg]` shortcode or the Document Gallery block without proper escaping (e.g., using `esc_attr()` or `esc_html()`).\n\nAn unauthenticated attacker can overwrite the plugin's configuration to include malicious JavaScript, which will then execute in the context of any user (including administrators) who visits a page containing a document gallery.\n\n## 2. Attack Vector Analysis\n-   **Endpoint:** `\u002Fwp-admin\u002Fadmin-post.php` (or any request triggering `admin_init`).\n-   **Vulnerable Action:** The settings save handler (likely triggered by a POST request containing the `document_gallery` parameter).\n-   **","gemini-3-flash-preview","2026-07-15 10:01:50","2026-07-15 10:03:26",{"type":36,"vulnerable_version":37,"fixed_version":11,"vulnerable_browse":38,"vulnerable_zip":39,"fixed_browse":40,"fixed_zip":41,"all_tags":42},"plugin","5.1.0","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fdocument-gallery\u002Ftags\u002F5.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdocument-gallery.5.1.0.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fdocument-gallery\u002Ftags\u002F5.1.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdocument-gallery.5.1.1.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fdocument-gallery\u002Ftags"]