plugin

New Grid Gallery Vulnerabilities

4 known security issues reported for the New Grid Gallery WordPress plugin. Most recent disclosed Apr 29, 2024.

1 critical 1 high 2 medium

Running New Grid Gallery on your site? Check whether your installed version is affected.

Scan your site free

Grid Gallery – Photo Image Grid Gallery <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection via shortcode

high

The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization via shortcode of untrusted input from the awl_gg_settings_ meta value. This makes it possible for authenticated attackers, with contributor access and ab...

CVSS:
7.5
Affected:
up to 1.4.3
Fixed in:
1.4.4
Disclosed:
Apr 29, 2024

CVE-2024-1897 on NVD →

Grid Gallery < 1.4.4 - Contributor+ PHP Object Injection via shortcode

critical
Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Apr 29, 2024

CVE-2024-1897 on NVD →

Grid Gallery – Photo Image Grid Gallery <= 1.2.4 - Stored Cross-Site Scripting

medium

The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.

CVSS:
5.4
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Jul 21, 2021

CVE-2021-24529 on NVD →

Grid Gallery < 1.2.5 - Authenticated Stored Cross Site Scripting (XSS)

medium
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Jul 21, 2021

CVE-2021-24529 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database