Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-92422 1 Wordpress-extensions 1 Meow Gallery 2026-09-28 6.5 Medium
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.
CVE-2026-92423 1 Wordpress-extensions 1 Meow Gallery 2026-09-28 2.7 Low
The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.