CVE-2026-92422EPSS p3.7%
CVE-2026-92422CVE-2026-92422
Description
The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| EPSS | 0.15% probability of exploitation · percentile 3.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-21 |