Skip to content
Multiple Vulnerabilities Found in Meow Gallery Plugin for WordPress

Multiple Vulnerabilities Found in Meow Gallery Plugin for WordPress

First seen 21 Sep 2026, 15:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 17:54 UTC
  • CVE-2026-92422 allows unauthenticated shortcode execution, rated 6.5/10.
  • CVE-2026-92423 enables information disclosure for authenticated users, rated 2.7/10.
  • Both vulnerabilities affect Meow Gallery plugin versions before 5.5.5.

Two vulnerabilities have been identified in the Meow Gallery WordPress plugin, affecting versions prior to 5.5.5. CVE-2026-92422, rated 6.5/10 on the CVSS scale, allows unauthenticated users to execute arbitrary shortcodes, potentially disclosing non-public gallery content. CVE-2026-92423, rated 2.7/10, enables authenticated users with Author-level access to disclose details of other users' draft and private posts. The vulnerabilities stem from improper sanitization and capability checks in the plugin. The estimated chance of exploitation for CVE-2026-92422 is low at 0.10% within 30 days. Both vulnerabilities were published on 2026-09-20. Users are advised to update to version 5.5.5 or later to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-26
CVE-2026-33413 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-22
CVE-2026-9245 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-20
CVE-2026-92422 published
A medium-severity vulnerability in Meow Gallery allows unauthenticated shortcode execution, exposing non-public content.
Strix.Ai
2026-09-20
CVE-2026-92423 published
A low-severity vulnerability in Meow Gallery allows authenticated users to disclose other users' draft and private post details.
Strix.Ai
2026-09-21
Users advised to update
Users of the Meow Gallery plugin are urged to update to version 5.5.5 or later to mitigate vulnerabilities.
Strix.Ai

More articles in this cluster (2)

Following this threat?

Track CVE-2026-33413 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed