CVE Database /
CVE-2026-13605
CVE
CVE-2026-13605 — PhotoSwipe [photo-swipe] <= 4.1.1.1 (unfixed + closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-13605
|
PhotoSwipe [photo-swipe] <= 4.1.1.1 (unfixed + closed) |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Unknown
|
< 4.1.1.1
|
4.1.1.1 |
2026-07-07 |
—
|
CVE-2026-13605
The PhotoSwipe WordPress plugin's caption feature is vulnerable due to its failure to properly sanitize user-submitted title attributes. When an author with sufficient privileges inserts malicious code into a link's title attribute, it can be injected into the page's DOM without being escaped. This allows an attacker to execute arbitrary JavaScript in the browser of any visitor who clicks the compromised link.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings