Gallery for Social Photo <= 1.0.0.35 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gallery for Social Photo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web s...
- CVSS:
- 6.4
- Affected:
- up to 1.0.0.36
- Fixed in:
- 1.0.0.37
- Disclosed:
- Mar 25, 2025
CVE-2025-26742 on NVD →
Gallery for Social Photo <= 1.0.0.25 - Subscriber+ SQL Injection
high
The plugin Gallery for Social Photo is vulnerable to SQL Injection via the post parameter in the function gifeed_duplicate_feed in versions up to, and including 1.0.0.25 due to insufficient sanitization before using it in an unprepared SQL query. This make it possible for subscribers to append additional SQL queries in...
- CVSS:
- 8.8
- Affected:
- up to 1.0.0.25
- Fixed in:
- 1.0.0.27
- Disclosed:
- May 24, 2022
Gallery for Social Photo <= 1.0.0.27 - Cross-Site Request Forgery to Post Duplication
medium
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it possible for unauthenticated attackers to duplicate existing posts or page...
- CVSS:
- 5.4
- Affected:
- up to 1.0.0.27
- Fixed in:
- 1.0.0.29
- Disclosed:
- May 24, 2022
CVE-2022-2224 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database