WordPress Gallery Plugin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The WordPress Gallery Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forg...
- CVSS:
- 6.1
- Affected:
- up to 1.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 16, 2025
CVE-2025-23842 on NVD →
WordPress Gallery Plugin [wordpress-gallery-plugin] <= 1.4 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Nilesh Shiragave WordPress Gallery Plugin allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin: from n/a through 1.4.
- Affected:
- up to 1.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 16, 2025
CVE-2025-23842 on NVD →
WordPress Gallery Plugin [wordpress-gallery-plugin] <= 1.4 (closed)
unknown
[en] Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
- Affected:
- up to 1.4
- Fixed in:
- 1.4
- Disclosed:
- Jan 22, 2020
CVE-2012-4919 on NVD →
WordPress Gallery Plugin [wordpress-gallery-plugin] < 1.2 (closed)
unknown
TimThumb WebShot plugin is prone to a remote code execution vulnerability, because of script does not check remotely cached files properly. Also, it can attack URL.
Upgrade the plugin.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Jun 24, 2014
WordPress Gallery Plugin <= 1.4 - Unauthenticated Remote File Inclusion
critical
The WordPress Gallery Plugin plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 1.4 via the 'load' parameter. This allows unauthenticated attackers to include remote files on the server, resulting in code execution.
- CVSS:
- 9.8
- Affected:
- up to 1.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 31, 2013
CVE-2012-4919 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database