CVE-2019-14790: Limbcode Limb-Gallery

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalleryAjax&grsAction=shortcode task parameter,

Affected products

  • Limbcode Limb-Gallery: up to and including 1.4.0

Published 2019-08-15. Last modified 2026-06-17.