Meow Gallery <= 5.5.1 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Meow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.2
- Disclosed:
- Aug 3, 2026
CVE-2026-15386 on NVD →
Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation
medium
The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 5.4.4
- Fixed in:
- 5.4.5
- Disclosed:
- Jun 12, 2026
CVE-2026-1291 on NVD →
Meow Gallery <= 5.4.4 - Authenticated (Author+) SQL Injection
medium
The Meow Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, t...
- CVSS:
- 6.5
- Affected:
- up to 5.4.4
- Fixed in:
- 5.4.5
- Disclosed:
- Feb 26, 2026
CVE-2026-32418 on NVD →
Meow Gallery <= 5.2.7 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Meow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- May 7, 2025
CVE-2025-47449 on NVD →
Meow Gallery [meow-gallery] < 5.2.8
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Meow Gallery allows Stored XSS. This issue affects Meow Gallery: from n/a through 5.2.7.
- Affected:
- up to 5.2.8
- Fixed in:
- 5.2.8
- Disclosed:
- May 7, 2025
CVE-2025-47449 on NVD →
Meow Gallery [meow-gallery] < 5.1.4
unknown
[en] The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data_atts’ parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permission...
- Affected:
- up to 5.1.4
- Fixed in:
- 5.1.4
- Disclosed:
- May 9, 2024
CVE-2024-4386 on NVD →
Gallery Block (Meow Gallery) <= 5.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data_atts’ parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and...
- CVSS:
- 6.4
- Affected:
- up to 5.1.3
- Fixed in:
- 5.1.4
- Disclosed:
- May 8, 2024
CVE-2024-4386 on NVD →
Meow Gallery [meow-gallery] < 4.1.9
unknown
[en] The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manip...
- Affected:
- up to 4.1.9
- Fixed in:
- 4.1.9
- Disclosed:
- Oct 4, 2021
CVE-2021-24465 on NVD →
Meow Gallery (+ Gallery Block) <= 4.1.9 - Missing Authorization to Arbitrary Options Update
high
The Meow Gallery plugin for WordPress is vulnerable to Arbitrary Options Update via the REST API in versions up to, and including, 4.1.9. This makes it possible for unauthenticated attackers to modify otherwise restricted arbitrary site options. This can be leveraged to create new administrative user accounts.
- CVSS:
- 8.8
- Affected:
- up to 4.1.9
- Fixed in:
- 4.2.0
- Disclosed:
- Sep 2, 2021
Meow Gallery (+ Gallery Block) <= 4.1.8 - SQL Injection
high
The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulate...
- CVSS:
- 8.1
- Affected:
- up to 4.1.9
- Fixed in:
- 4.1.9
- Disclosed:
- Sep 2, 2021
CVE-2021-24465 on NVD →
Meow Gallery [meow-gallery] < 4.2.0
unknown
The Meow Gallery plugin for WordPress is vulnerable to Arbitrary Options Update via the REST API in versions up to, and including, 4.1.9. This makes it possible for unauthenticated attackers to modify otherwise restricted arbitrary site options. This can be leveraged to create new administrative user accounts.
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.0
- Disclosed:
- Sep 2, 2021
Meow Gallery [meow-gallery] < 4.2.0
unknown
The plugin does not properly check for capability in its REST API, allowing
- Any authenticated user with the upload_file capability (such as author+) to call them in versions before 4.1.9
- Any unauthenticated user to call them except the rest_all_settings endpoint, in 4.1.9
One endpoint in particular could be us...
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database