plugin

Feed Instagram Lite Vulnerabilities

3 known security issues reported for the Feed Instagram Lite WordPress plugin. Most recent disclosed Mar 25, 2025.

1 high 2 medium

Running Feed Instagram Lite on your site? Check whether your installed version is affected.

Scan your site free

Gallery for Social Photo <= 1.0.0.35 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Gallery for Social Photo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 1.0.0.36
Fixed in:
1.0.0.37
Disclosed:
Mar 25, 2025

CVE-2025-26742 on NVD →

Gallery for Social Photo <= 1.0.0.25 - Subscriber+ SQL Injection

high

The plugin Gallery for Social Photo is vulnerable to SQL Injection via the post parameter in the function gifeed_duplicate_feed in versions up to, and including 1.0.0.25 due to insufficient sanitization before using it in an unprepared SQL query. This make it possible for subscribers to append additional SQL queries in...

CVSS:
8.8
Affected:
up to 1.0.0.25
Fixed in:
1.0.0.27
Disclosed:
May 24, 2022

Gallery for Social Photo <= 1.0.0.27 - Cross-Site Request Forgery to Post Duplication

medium

The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it possible for unauthenticated attackers to duplicate existing posts or page...

CVSS:
5.4
Affected:
up to 1.0.0.27
Fixed in:
1.0.0.29
Disclosed:
May 24, 2022

CVE-2022-2224 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database