Multiple Vulnerabilities Found in Meow Gallery Plugin for WordPress
Article Content
- •CVE-2026-92422 allows unauthenticated shortcode execution, rated 6.5/10.
- •CVE-2026-92423 enables information disclosure for authenticated users, rated 2.7/10.
- •Both vulnerabilities affect Meow Gallery plugin versions before 5.5.5.
Two vulnerabilities have been identified in the Meow Gallery WordPress plugin, affecting versions prior to 5.5.5. CVE-2026-92422, rated 6.5/10 on the CVSS scale, allows unauthenticated users to execute arbitrary shortcodes, potentially disclosing non-public gallery content. CVE-2026-92423, rated 2.7/10, enables authenticated users with Author-level access to disclose details of other users' draft and private posts. The vulnerabilities stem from improper sanitization and capability checks in the plugin. The estimated chance of exploitation for CVE-2026-92422 is low at 0.10% within 30 days. Both vulnerabilities were published on 2026-09-20. Users are advised to update to version 5.5.5 or later to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-33413 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Vulnerabilities in SxDevOps Expose Remote Code Execution Risks On September 20, 2026, multiple critical vulnerabilities were disclosed in SxDevOps versions 1.0 and 1.1, including CVE-2026-93970, CVE-2026-93969, and CVE-2026-93971. These vulnerabilities allow for remote code execution (RCE) and the exploitation of hardcoded credentials, posing significant risks to organizations…