Riosis Private Limited Rio Photo Gallery Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Rio Photo Gallery plugin by Riosis Private Limited, affecting versions through 0.1. This issue allows attackers to inject malicious scripts that are executed when users visit the affected page.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser.

Remediation

Users of the Rio Photo Gallery plugin are advised to update to a version later than 0.1, if available. For those using WordPress, Patchstack has issued a virtual patch that automatically mitigates this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorith