What is CVE-2026-12982?
CVE-2026-12982 is a Reflected Cross-Site Scripting vulnerability in the Document Gallery WordPress plugin, where user input is improperly sanitized and escaped before being reflected in an unauthenticated AJAX response. This allows exploitation against unauthenticated users, affecting plugin versions prior to 5.1.1, and immediate update is recommended.
Azərbaycanca: CVE-2026-12982, Document Gallery WordPress plaginində aşkarlanan Reflected Cross-Site Scripting zəifliyidir. Bu boşluq, autentifikasiya olunmamış istifadəçilərə qarşı istismar edilə bilər, çünki plaginq istifadəçi daxiletməsini düzgün təmizləmədən AJAX cavabında əks etdirir. Plaginin 5.1.1-dən əvvəlki versiyaları təsirlənir, dərhal yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
What can an attacker do without authentication by exploiting CVE-2026-12982?
An attacker can execute a Reflected Cross-Site Scripting (XSS) attack against unauthenticated users because the Document Gallery plugin reflects user input in an AJAX response without properly sanitizing and escaping it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.