Vulnerability in Photo Gallery – Responsive Image Galleries by Supsystic — CVE-2026-102399
MediumSeverity
—Estimated exploit probability
20,000+ sitesInstalls
1.21.1Fixed in
What to do now
Update Photo Gallery – Responsive Image Galleries by Supsystic to 1.21.1 or later.
Affected versions
- Everything up to and including 1.21.0
Affected: Photo Gallery – Responsive Image Galleries by Supsystic (plugin, gallery-by-supsystic)
What the vulnerability is
The Photo Gallery – Responsive Image Galleries by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.21.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.