The Meow Gallery WordPress plugin before 5.5.5 does not...
Moderate severity
Unreviewed
Published
Sep 20, 2026
to the GitHub Advisory Database
•
Updated Sep 20, 2026
Description
Published by the National Vulnerability Database
Sep 20, 2026
Published to the GitHub Advisory Database
Sep 20, 2026
Last updated
Sep 20, 2026
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.
References