PT-2025-29215 · Gphotos+7 · Gphotos+8

Aurélien Bourdois

·

Published

2025-07-11

·

Updated

2025-07-11

·

CVE-2025-6716

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress versions through 26.0.8
Description: The WordPress plugin is susceptible to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping. This allows authenticated attackers with Author-level access or higher to inject arbitrary web scripts into pages. These scripts will execute when a user accesses the injected page.
Recommendations: Versions prior to 26.0.9 are vulnerable. Update to version 26.0.9 or later to address the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-6716

Affected Products

Ecommerce Contest Gallery – Upload
Files
Instagram
Openai Plugin For Wordpress
Gphotos
Social Share Buttons
Tiktok
Twitter
Youtube