Gallery – Photo Albums Plugin <= 1.3.170 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gallery – Photo Albums Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.170 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 1.3.170
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31586 on NVD →
Gallery – Photo Albums Plugin < 1.3.47 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Media Subtitle fields.
- CVSS:
- 6.1
- Affected:
- up to 1.3.50
- Fixed in:
- 1.3.50
- Disclosed:
- Sep 5, 2015
CVE-2015-7386 on NVD →
Gallery – Photo Albums Plugin < 1.3.03 - Multiple Cross-Site Request Forgery
medium
The Gallery – Photo Albums Plugin for WordPress is vulnerable to Multiple Cross-Site Request Forgery in versions before 1.3.03. This is due to missing or incorrect nonce validation on the easymedia_imgresize_ajax() AJAX function. This makes it possible for unauthenticated attackers to resize images via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 1.3.03
- Fixed in:
- 1.3.03
- Disclosed:
- Sep 1, 2014
Gallery – Photo Albums Plugin < 1.2.29 - Cross-Site Scripting
medium
The Gallery – Photo Albums (formerly titled Easy Media Gallery) Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spg_add_admin function in versions up to, and including, 1.2.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with a...
- CVSS:
- 5.5
- Affected:
- up to 1.2.29
- Fixed in:
- 1.2.29
- Disclosed:
- Dec 17, 2013
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database