CVE-2023-0764: Bestwebsoft Gallery

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.

Affected products

Published 2023-04-17. Last modified 2026-06-17.