Album Gallery – WordPress Gallery [new-album-gallery] < 1.6.4
unknown
[en] The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No k...
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Mar 1, 2025
CVE-2024-13833 on NVD →
Album Gallery – WordPress Gallery <= 1.6.3 - Authenticated (Editor+) PHP Object Injection via Gallery Meta
high
The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known...
- CVSS:
- 7.2
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Feb 28, 2025
CVE-2024-13833 on NVD →
Album Gallery – WordPress Gallery [new-album-gallery] < 1.5.8
unknown
[en] Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a through 1.5.7.
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Jun 10, 2024
CVE-2024-35720 on NVD →
Album Gallery – WordPress Gallery <= 1.5.7 - Missing Authorization
medium
The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_album_gallery and _ag_save_settings functions in versions up to, and including, 1.5.7. This makes it possible for authenticated attackers, with subscriber-level ac...
- CVSS:
- 4.3
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Jun 6, 2024
CVE-2024-35720 on NVD →
Album Gallery – WordPress Gallery [new-album-gallery] < 1.5.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.0
- Disclosed:
- Jul 17, 2023
CVE-2023-23646 on NVD →
Album Gallery – WordPress Gallery <= 1.4.9 - Cross-Site Request Forgery via album-gallery-column-settings.php
medium
The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.9. This is due to missing or incorrect nonce validation when updating setting on the album-gallery-column-settings.php page. This makes it possible for unauthenticated attackers t...
- CVSS:
- 4.3
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.0
- Disclosed:
- Apr 19, 2023
CVE-2023-23646 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database