plugin

New Album Gallery Vulnerabilities

6 known security issues reported for the New Album Gallery WordPress plugin. Most recent disclosed Mar 1, 2025.

1 high 2 medium

Running New Album Gallery on your site? Check whether your installed version is affected.

Scan your site free

Album Gallery &#8211; WordPress Gallery [new-album-gallery] < 1.6.4

unknown

[en] The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No k...

Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Mar 1, 2025

CVE-2024-13833 on NVD →

Album Gallery – WordPress Gallery <= 1.6.3 - Authenticated (Editor+) PHP Object Injection via Gallery Meta

high

The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known...

CVSS:
7.2
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Feb 28, 2025

CVE-2024-13833 on NVD →

Album Gallery &#8211; WordPress Gallery [new-album-gallery] < 1.5.8

unknown

[en] Missing Authorization vulnerability in A WP Life Album Gallery – WordPress Gallery.This issue affects Album Gallery – WordPress Gallery: from n/a through 1.5.7.

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Jun 10, 2024

CVE-2024-35720 on NVD →

Album Gallery – WordPress Gallery <= 1.5.7 - Missing Authorization

medium

The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_album_gallery and _ag_save_settings functions in versions up to, and including, 1.5.7. This makes it possible for authenticated attackers, with subscriber-level ac...

CVSS:
4.3
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Jun 6, 2024

CVE-2024-35720 on NVD →

Album Gallery &#8211; WordPress Gallery [new-album-gallery] < 1.5.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Jul 17, 2023

CVE-2023-23646 on NVD →

Album Gallery – WordPress Gallery <= 1.4.9 - Cross-Site Request Forgery via album-gallery-column-settings.php

medium

The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.9. This is due to missing or incorrect nonce validation when updating setting on the album-gallery-column-settings.php page. This makes it possible for unauthenticated attackers t...

CVSS:
4.3
Affected:
up to 1.4.9
Fixed in:
1.5.0
Disclosed:
Apr 19, 2023

CVE-2023-23646 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database