Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Photoswipe
Photoswipe photoswipe Wordpress Wordpress wordpress |
|
| Vendors & Products |
Photoswipe
Photoswipe photoswipe Wordpress Wordpress wordpress |
Wed, 29 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 29 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link. | |
| Title | Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-29T12:46:24.654Z
Reserved: 2026-06-29T08:32:22.616Z
Link: CVE-2026-13605
Updated: 2026-07-29T12:45:36.975Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T12:45:05Z