MEDIUM (6.1)
    Plugin

    Gallagher Website Design Plugin Stored Cross-Site Scripting Vulnerability

    Published Date: 4/22/2026
    CVE ID: CVE-2026-1913

    Summary

    The Gallagher Website Design plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization in the 'prefix' attribute of the login_link shortcode. This flaw allows Contributor-level users and above to inject arbitrary scripts into pages, potentially executing malicious code when accessed by users.

    Vulnerability Details

    Stored Cross-Site Scripting (XSS) vulnerabilities occur when user-supplied input is not properly sanitized before being stored on the server and subsequently returned to users' browsers. In this case, the Gallagher Website Design plugin fails to adequately sanitize and escape the 'prefix' attribute in the login_link shortcode, which is utilized in generating customized login links. As a result, authenticated users with at least Contributor-level permissions can inject malicious scripts into pages. When other users visit these pages, the scripts execute in their browsers, potentially leading to unauthorized actions being performed or sensitive information being disclosed. This vulnerability affects all plugin versions up to and including 2.6.4, and it poses a significant risk by compromising the integrity and security of websites using this plugin.

    Recommendations

    To mitigate this vulnerability, site administrators should restrict shortcode usage to trusted user roles only or disable the feature entirely until a patch is applied. Consider using additional security plugins to monitor for unwanted shortcode usage. It's also advisable to implement Content Security Policy (CSP) headers to reduce the impact of XSS vulnerabilities.

    Available Fixes

    Last Updated: 4/25/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More