CVE

CVE-2026-13605 — PhotoSwipe [photo-swipe] <= 4.1.1.1 (unfixed + closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13605 PhotoSwipe [photo-swipe] <= 4.1.1.1 (unfixed + closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 4.1.1.1 4.1.1.1 2026-07-07

CVE-2026-13605

The PhotoSwipe WordPress plugin's caption feature is vulnerable due to its failure to properly sanitize user-submitted title attributes. When an author with sufficient privileges inserts malicious code into a link's title attribute, it can be injected into the page's DOM without being escaped. This allows an attacker to execute arbitrary JavaScript in the browser of any visitor who clicks the compromised link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.