plugin

Wordpress Gallery Plugin Vulnerabilities

5 known security issues reported for the Wordpress Gallery Plugin WordPress plugin. Most recent disclosed Jan 16, 2025.

1 critical 1 medium

Running Wordpress Gallery Plugin on your site? Check whether your installed version is affected.

Scan your site free

WordPress Gallery Plugin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The WordPress Gallery Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forg...

CVSS:
6.1
Affected:
up to 1.4
Fix:
No patched version reported
Disclosed:
Jan 16, 2025

CVE-2025-23842 on NVD →

WordPress Gallery Plugin [wordpress-gallery-plugin] <= 1.4 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Nilesh Shiragave WordPress Gallery Plugin allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin: from n/a through 1.4.

Affected:
up to 1.4
Fix:
No patched version reported
Disclosed:
Jan 16, 2025

CVE-2025-23842 on NVD →

WordPress Gallery Plugin [wordpress-gallery-plugin] <= 1.4 (closed)

unknown

[en] Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
Jan 22, 2020

CVE-2012-4919 on NVD →

WordPress Gallery Plugin [wordpress-gallery-plugin] < 1.2 (closed)

unknown

TimThumb WebShot plugin is prone to a remote code execution vulnerability, because of script does not check remotely cached files properly. Also, it can attack URL. Upgrade the plugin.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Jun 24, 2014

WordPress Gallery Plugin <= 1.4 - Unauthenticated Remote File Inclusion

critical

The WordPress Gallery Plugin plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 1.4 via the 'load' parameter. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.

CVSS:
9.8
Affected:
up to 1.4
Fix:
No patched version reported
Disclosed:
Jan 31, 2013

CVE-2012-4919 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database