What is CVE-2026-13605?
The plugin writes the title attribute of user-supplied link markup into the DOM without escaping, using it as a lightbox caption. This attribute survives post-content sanitization for users lacking the 'unfiltered_html' capability, potentially leading to Stored XSS attacks. Site administrators should update the PhotoSwipe plugin to the latest version.
Azərbaycanca: Plugin istifadəçi tərəfindən təqdim olunan keçid açıqlamasını (title attribute) DOM-a qaçırılmadan (escaping) yazır. Bu, 'unfiltered_html' icazəsi olmayan istifadəçilər üçün post məzmun təmizlənməsindən (sanitization) sonra da davam edir, nəticədə saxlanılmış XSS hücumlarına səbəb ola bilər. Sayt adminlərinə PhotoSwipe plaginini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by the CVE-2026-13605 vulnerability?
This vulnerability affects the PhotoSwipe plugin. Site administrators are advised to update the plugin to the latest version.
Why is the CVE-2026-13605 vulnerability dangerous for users without the 'unfiltered_html' capability?
The plugin writes the title attribute of user-supplied link markup into the DOM without escaping. This attribute survives post-content sanitization for users lacking the 'unfiltered_html' capability, potentially leading to Stored XSS attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.