Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys
high
The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, 4.7.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The `gllr_...
- CVSS:
- 7.2
- Affected:
- up to 4.7.9
- Fixed in:
- 4.8.0
- Disclosed:
- Aug 15, 2026
CVE-2026-2497 on NVD →
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.7.8 - Authenticated (Contributor+) SQL Injection
medium
The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible f...
- CVSS:
- 6.5
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.9
- Disclosed:
- Jun 26, 2026
CVE-2026-57642 on NVD →
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 4.7.4
unknown
[en] The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via deserialization of untrusted input in the 'import_gallery_from_csv' function. This makes it possible for authenticated attacke...
- Affected:
- up to 4.7.4
- Fixed in:
- 4.7.4
- Disclosed:
- Mar 7, 2025
CVE-2024-13906 on NVD →
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection
high
The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via deserialization of untrusted input in the 'import_gallery_from_csv' function. This makes it possible for authenticated attackers, w...
- CVSS:
- 7.2
- Affected:
- up to 4.7.3
- Fixed in:
- 4.7.4
- Disclosed:
- Mar 6, 2025
CVE-2024-13906 on NVD →
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 4.7.0
unknown
[en] The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be install...
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.0
- Disclosed:
- Apr 17, 2023
CVE-2023-0765 on NVD →
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 4.7.0
unknown
[en] The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.0
- Disclosed:
- Apr 17, 2023
CVE-2023-0764 on NVD →
Gallery by BestWebSoft <= 4.6.9 - Authenticated (Author+) SQL Injection
high
The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for author-level attackers to append additional SQL qu...
- CVSS:
- 8.8
- Affected:
- up to 4.6.9
- Fixed in:
- 4.7.0
- Disclosed:
- Mar 27, 2023
CVE-2023-0765 on NVD →
Gallery by BestWebSoft <= 4.6.9 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Gallery by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via gallery information in versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 4.6.9
- Fixed in:
- 4.7.0
- Disclosed:
- Mar 27, 2023
CVE-2023-0764 on NVD →
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 4.7.0
unknown
Update the WordPress Gallery plugin to the latest available version (at least 4.7.0).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gallery Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads int...
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.0
- Disclosed:
- Mar 27, 2023
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.6.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Gallery by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...
- CVSS:
- 4.4
- Affected:
- up to 4.6.9
- Fixed in:
- 4.7.0
- Disclosed:
- Mar 23, 2023
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 4.7.0
unknown
The Gallery by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.0
- Disclosed:
- Mar 23, 2023
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 4.5.0
unknown
[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.0
- Disclosed:
- May 22, 2017
CVE-2017-2171 on NVD →
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress < 4.5.0 - Reflected Cross-Site Scripting
medium
The Gallery by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 6.1
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.0
- Disclosed:
- Apr 12, 2017
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 4.5.0
unknown
The Gallery by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘category’ parameter in versions before 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.0
- Disclosed:
- Apr 12, 2017
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 3.8.4
unknown
This plugin is prone to an arbitrary file access in gallery-plugin.php filename_1 parameter. It allows attackers to read arbitrary files.
Upgrade plugin.
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- May 15, 2015
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 3.8.4
unknown
WordPress Gallery plugin is prone to a remote arbitrary file access vulnerability that allows an attacker to read arbitrary files. Other attacks are also possible.
Update the plugin.
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Jan 10, 2013
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 3.07
unknown
WordPress Gallery plugin is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible.
Update the plugin.
- Affected:
- up to 3.07
- Fixed in:
- 3.07
- Disclosed:
- Jun 6, 2012
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 4.5.0
unknown
- Affected:
- up to 4.5.0
- Fixed in:
- 4.5.0
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress [gallery-plugin] < 3.1.1
unknown
The Gallery by BestWebSoft WordPress plugin was affected by an Unauthenticated File Upload PHP Code Execution security vulnerability.
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database