PT-2026-65692 · Undefined · Undefined

·

CVE-2026-13605

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13605

Affected Products

Undefined