plugin

Meow Gallery Vulnerabilities

12 known security issues reported for the Meow Gallery WordPress plugin. Most recent disclosed Aug 3, 2026.

2 high 5 medium

Running Meow Gallery on your site? Check whether your installed version is affected.

Scan your site free

Meow Gallery <= 5.5.1 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Meow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
6.4
Affected:
up to 5.5.1
Fixed in:
5.5.2
Disclosed:
Aug 3, 2026

CVE-2026-15386 on NVD →

Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation

medium

The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above,...

CVSS:
4.3
Affected:
up to 5.4.4
Fixed in:
5.4.5
Disclosed:
Jun 12, 2026

CVE-2026-1291 on NVD →

Meow Gallery <= 5.4.4 - Authenticated (Author+) SQL Injection

medium

The Meow Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, t...

CVSS:
6.5
Affected:
up to 5.4.4
Fixed in:
5.4.5
Disclosed:
Feb 26, 2026

CVE-2026-32418 on NVD →

Meow Gallery <= 5.2.7 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Meow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
6.4
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
May 7, 2025

CVE-2025-47449 on NVD →

Meow Gallery [meow-gallery] < 5.2.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Meow Gallery allows Stored XSS. This issue affects Meow Gallery: from n/a through 5.2.7.

Affected:
up to 5.2.8
Fixed in:
5.2.8
Disclosed:
May 7, 2025

CVE-2025-47449 on NVD →

Meow Gallery [meow-gallery] < 5.1.4

unknown

[en] The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data_atts’ parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permission...

Affected:
up to 5.1.4
Fixed in:
5.1.4
Disclosed:
May 9, 2024

CVE-2024-4386 on NVD →

Gallery Block (Meow Gallery) <= 5.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data_atts’ parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and...

CVSS:
6.4
Affected:
up to 5.1.3
Fixed in:
5.1.4
Disclosed:
May 8, 2024

CVE-2024-4386 on NVD →

Meow Gallery [meow-gallery] < 4.1.9

unknown

[en] The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manip...

Affected:
up to 4.1.9
Fixed in:
4.1.9
Disclosed:
Oct 4, 2021

CVE-2021-24465 on NVD →

Meow Gallery (+ Gallery Block) <= 4.1.9 - Missing Authorization to Arbitrary Options Update

high

The Meow Gallery plugin for WordPress is vulnerable to Arbitrary Options Update via the REST API in versions up to, and including, 4.1.9. This makes it possible for unauthenticated attackers to modify otherwise restricted arbitrary site options. This can be leveraged to create new administrative user accounts.

CVSS:
8.8
Affected:
up to 4.1.9
Fixed in:
4.2.0
Disclosed:
Sep 2, 2021

Meow Gallery (+ Gallery Block) <= 4.1.8 - SQL Injection

high

The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulate...

CVSS:
8.1
Affected:
up to 4.1.9
Fixed in:
4.1.9
Disclosed:
Sep 2, 2021

CVE-2021-24465 on NVD →

Meow Gallery [meow-gallery] < 4.2.0

unknown

The Meow Gallery plugin for WordPress is vulnerable to Arbitrary Options Update via the REST API in versions up to, and including, 4.1.9. This makes it possible for unauthenticated attackers to modify otherwise restricted arbitrary site options. This can be leveraged to create new administrative user accounts.

Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Sep 2, 2021

Meow Gallery [meow-gallery] < 4.2.0

unknown

The plugin does not properly check for capability in its REST API, allowing - Any authenticated user with the upload_file capability (such as author+) to call them in versions before 4.1.9 - Any unauthenticated user to call them except the rest_all_settings endpoint, in 4.1.9 One endpoint in particular could be us...

Affected:
up to 4.2.0
Fixed in:
4.2.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database