The Gallagher Website Design plugin for WordPress is affected by a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization in the 'prefix' attribute of the login_link shortcode. This flaw allows Contributor-level users and above to inject arbitrary scripts into pages, potentially executing malicious code when accessed by users.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.