Grid Gallery – Photo Image Grid Gallery <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection via shortcode
high
The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization via shortcode of untrusted input from the awl_gg_settings_ meta value. This makes it possible for authenticated attackers, with contributor access and ab...
- CVSS:
- 7.5
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Apr 29, 2024
CVE-2024-1897 on NVD →
Grid Gallery < 1.4.4 - Contributor+ PHP Object Injection via shortcode
critical
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Apr 29, 2024
CVE-2024-1897 on NVD →
Grid Gallery – Photo Image Grid Gallery <= 1.2.4 - Stored Cross-Site Scripting
medium
The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.
- CVSS:
- 5.4
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Jul 21, 2021
CVE-2021-24529 on NVD →
Grid Gallery < 1.2.5 - Authenticated Stored Cross Site Scripting (XSS)
medium
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Jul 21, 2021
CVE-2021-24529 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database