Skip to content
CVE-2026-92422: Meow Gallery Vulnerability (CVSS 6.5)

CVE-2026-92422: Meow Gallery Vulnerability (CVSS 6.5)

Strix.Ai September 20, 2026

CVE-2026-92422 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale . The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content. . EPSS estimates a 0.10% chance of exploitation in the 30 days.

The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Source: CNA advisory (CVE.org). NVD analysis pending.

Frequently Asked Questions

Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8n Strix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.

Autonomous Pentesting AI agents that find and validate exploitable vulnerabilities like this one across your applications.

PR Reviews Pentest every pull request so vulnerable code is caught before it ships to production.

AI Penetration Testing How AI-driven penetration testing continuously covers your attack surface.

Related CVEs from 2026

CVE-2026-92416 A vulnerability has been found in Open5GS up to 2.8.0. Affec… 4.3

CVE-2026-92417 A vulnerability was found in Open5GS up to 2.8.0. This affec… 6.5

CVE-2026-92418 A vulnerability was determined in ChangeWeDer crm up to c07b… 3.5

CVE-2026-9242 The RegistrationMagic – Custom Registration Forms, User Regi… 5.3

CVE-2026-92420 The Hydra Booking — Appointment Scheduling & Booking Calenda… 3.8

CVE-2026-92421 The Hydra Booking — Appointment Scheduling & Booking Calenda… 4.7

CVE-2026-92423 The Meow Gallery WordPress plugin before 5.5.5 does not perf… 2.7

CVE-2026-92425 The Hydra Booking — Appointment Scheduling & Booking Calenda… 5.5

CVE-2026-9243 The Plus Addons for Elementor plugin for WordPress is vulner… 6.4

CVE-2026-92430 The Rede Itaú for WooCommerce — Payment PIX, Credit Card and… 5.3

CVE-2026-92435 The Mailchimp for WooCommerce WordPress plugin before 6.1.1 … 5.3

CVE-2026-9244 Rejected reason: This CVE ID has been rejected or withdrawn …

Are you affected by CVE-2026-92422 ?

Run a free Strix scan to check your systems for this vulnerability.