What is CVE-2026-15386?
This vulnerability exists in the Meow Gallery WordPress plugin before version 5.5.2. The plugin does not escape an attachment's alt text before outputting it into a link attribute for linked galleries, allowing users with Author role or above to store a JavaScript payload. This payload then executes in the browser of any visitor, leading to a Stored XSS attack. Sites using the plugin should immediately update to version 5.5.2 or newer.
Azərbaycanca: Bu zəiflik Meow Gallery WordPress plaginində 5.5.2 versiyasından əvvəl mövcuddur. Plagin, əlavə edilmiş faylların alt mətnini link atributuna yerləşdirməzdən əvvəl düzgün escap etmir. Bu səbəbdən, Author və ya daha yüksək rola malik istifadəçi JavaScript yükü yerləşdirə bilər ki, bu da qalereyanı ziyarət edən istənilən şəxsin brauzerində icra olunar. Plagindən istifadə edən saytlar dərhal 5.5.2 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What type of attack does the CVE-2026-15386 vulnerability in the Meow Gallery plugin lead to?
It leads to a Stored XSS attack. The plugin executes the JavaScript payload stored by a user with the Author role in the browser of any visitor to the gallery.
To which version should the Meow Gallery plugin be updated to protect against CVE-2026-15386?
It should be updated to version 5.5.2 or newer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.