WordPress security by component
Meta-box GalleryMeta
Plugin description
Meta-box GalleryMeta is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jan 24, 2026; the highest CVE/CNA score is 4.4.
Plugin slug:
meta-box-gallerymetaLatest vulnerability
CVE-2026-1302: Meta-box GalleryMeta: Cross-site scripting
Meta-box GalleryMeta is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Jan 24, 2026 |
CVE-2026-1302
Meta-box GalleryMeta: Cross-site scripting
Meta-box GalleryMeta is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Jan 24, 2026 |
CVE-2026-0687
Meta-box GalleryMeta: A security weakness
Meta-box GalleryMeta is affected by a security weakness. Exploitation requires at least author-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|