VYPR

Gallery Plugin for WordPress

by WordPress

CVEs (6)

  • CVE-2023-3154HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

  • CVE-2023-3155HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

  • CVE-2025-23842HigJan 16, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Nilesh Shiragave WordPress Gallery Plugin wordpress-gallery-plugin allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin: from n/a through <= 1.4.

  • CVE-2024-3632MedJul 13, 2024
    risk 0.44cvss 6.8epss 0.00

    The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1946MedJul 4, 2022
    risk 0.40cvss 6.1epss 0.02

    The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

  • CVE-2023-3279MedOct 16, 2023
    risk 0.32cvss 4.9epss 0.01

    The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks