plugin

Wp Easy Gallery Vulnerabilities

32 known security issues reported for the Wp Easy Gallery WordPress plugin. Most recent disclosed Oct 1, 2024.

2 critical 4 high 4 medium

Running Wp Easy Gallery on your site? Check whether your installed version is affected.

Scan your site free

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] <= 4.8.5 (unfixed + closed)

unknown

[en] The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

Affected:
up to 4.8.5
Fix:
No patched version reported
Disclosed:
Oct 1, 2024

CVE-2024-9018 on NVD →

WP Easy Gallery <= 4.8.5 - Authenticated (Contributor+) SQL Injection via key Parameter

high

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possi...

CVSS:
8.8
Affected:
up to 4.8.5
Fix:
No patched version reported
Disclosed:
Sep 30, 2024

CVE-2024-9018 on NVD →

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] <= 4.8.5 (unfixed + closed)

unknown

[en] The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, wi...

Affected:
up to 4.8.5
Fix:
No patched version reported
Disclosed:
Sep 24, 2024

CVE-2024-8437 on NVD →

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] <= 4.8.5 (unfixed + closed)

unknown

[en] The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...

Affected:
up to 4.8.5
Fix:
No patched version reported
Disclosed:
Sep 24, 2024

CVE-2024-8436 on NVD →

WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection

critical

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...

CVSS:
9.9
Affected:
up to 4.8.5
Fix:
No patched version reported
Disclosed:
Sep 23, 2024

CVE-2024-8436 on NVD →

WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subscriber+) Gallery Manipulation

medium

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with su...

CVSS:
4.3
Affected:
up to 4.8.5
Fix:
No patched version reported
Disclosed:
Sep 23, 2024

CVE-2024-8437 on NVD →

WP Easy Gallery <= 4.1.4 - Stored Cross-Site Scripting

medium

The WP Easy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_style’ parameter in versions before 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute whenever a...

CVSS:
6.5
Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Jan 26, 2016

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 4.1.5 (closed)

unknown

The WP Easy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_style’ parameter in versions before 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute whenever a...

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Jan 26, 2016

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 4.1.5 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Jan 26, 2016

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.3 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Jan 26, 2016

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.3 (closed)

unknown

This plugin is prone to a cross site request forgery vulnerability. Upgrade this plugin.

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Jan 26, 2016

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

This plugin is prone to SQL injection via admin/overview.php galleryId parameter and admin/add-images.php multiple parameter. Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
May 15, 2015

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

This plugin is prone to multiple admin function cross site request forgery vulnerability. Update plugin.

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
May 15, 2015

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 4.1.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
May 14, 2015

WP Easy Gallery <= 2.7 - Cross-Site Request Forgery

high

The WP Easy Gallery for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged...

CVSS:
8.8
Affected:
up to 2.7
Fixed in:
2.7.1
Disclosed:
Aug 1, 2014

WP Easy Gallery <= 2.7 - SQL Injection

high

The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' parameter in the 'admin/overview.php' file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it po...

CVSS:
7.2
Affected:
up to 2.7
Fixed in:
2.7.1
Disclosed:
Aug 1, 2014

WP Easy Gallery <= 2.7 - SQL Injection

high

The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' parameters found in the ‘admin/add-images.php’ file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing...

CVSS:
7.2
Affected:
up to 2.7
Fixed in:
2.7.1
Disclosed:
Aug 1, 2014

WP Easy Gallery <= 1.7 - Cross-Site Scripting

medium

The WP Easy Gallery plugin for WordPress is vulnerable to Cross-Site Scripting via the 'select_gallery' and 'galleryId' parameters in versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that e...

CVSS:
6.1
Affected:
up to 1.7
Fixed in:
1.8
Disclosed:
Aug 1, 2014

PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

CVSS:
6.1
Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Aug 1, 2014

CVE-2013-6837 on NVD →

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

The WP Easy Gallery for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged...

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Aug 1, 2014

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' parameters found in the ‘admin/add-images.php’ file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing...

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Aug 1, 2014

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' parameter in the 'admin/overview.php' file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it po...

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Aug 1, 2014

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 1.8 (closed)

unknown

The WP Easy Gallery plugin for WordPress is vulnerable to Cross-Site Scripting via the 'select_gallery' and 'galleryId' parameters in versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that e...

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
Aug 1, 2014

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 4.1.1 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Dec 19, 2013

CVE-2013-6837 on NVD →

WP Easy Gallery <= 2.7 - SQL Injection

critical

The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' parameters found in the ‘admin/edit-gallery.php’ file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existi...

CVSS:
9.1
Affected:
up to 2.7
Fixed in:
2.7.1
Disclosed:
Feb 18, 2013

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' parameters found in the ‘admin/edit-gallery.php’ file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existi...

Affected:
up to 2.7.1
Fixed in:
2.7.1
Disclosed:
Feb 18, 2013

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 4.1.5 (closed)

unknown

The WP Easy Gallery &ndash; WordPress Gallery Plugin WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 4.1.5
Fixed in:
4.1.5

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.3 (closed)

unknown

The WP Easy Gallery &ndash; WordPress Gallery Plugin WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.7.3
Fixed in:
2.7.3

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.3 (closed)

unknown

The WP Easy Gallery &ndash; WordPress Gallery Plugin WordPress plugin was affected by a Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 2.7.3
Fixed in:
2.7.3

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

The WP Easy Gallery &ndash; WordPress Gallery Plugin WordPress plugin was affected by an admin/add-images.php Multiple Parameter SQL Injection security vulnerability.

Affected:
up to 2.7.1
Fixed in:
2.7.1

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

The WP Easy Gallery &ndash; WordPress Gallery Plugin WordPress plugin was affected by an admin/overview.php galleryId Parameter SQL Injection security vulnerability.

Affected:
up to 2.7.1
Fixed in:
2.7.1

WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed)

unknown

The WP Easy Gallery &ndash; WordPress Gallery Plugin WordPress plugin was affected by a Multiple Admin Function CSRF security vulnerability.

Affected:
up to 2.7.1
Fixed in:
2.7.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database