sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total17
Critical0
High5
Medium12
Reset
Showing 1-17 of 17 records
Threat Entry Updated 2026-06-17

Gallery - Broken Access Control (CVE-2025-12377)

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.12.0. This makes it possible for authenticated attackers, with Author-level access and above, to perform multiple actions, such as removing images from arbitrary galleries. The vulnerability was partially patched in version 1.12.0.

PLUGIN Gallery

CVE-2025-12377

MEDIUM CVSS 4.3 2025-11-13
Threat Entry Updated 2026-06-17

Gallery - Broken Access Control (CVE-2025-11448)

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/envira-convert/v1/bulk-convert' REST API endpoint in all versions up to, and including, 1.11.0. This makes it possible for authenticated attackers, with contributor-level access and above, to convert galleries to Envira galleries.

PLUGIN Gallery

CVE-2025-11448

MEDIUM CVSS 4.3 2025-11-08
Threat Entry Updated 2026-06-17

Gallery - Broken Access Control (CVE-2023-45631)

Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

PLUGIN Gallery

CVE-2023-45631

MEDIUM CVSS 4.3 2025-01-02
Threat Entry Updated 2026-06-17

Gallery - PHP Object Injection (CVE-2024-11501)

The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via deserialization of untrusted input from wd_gallery_$id parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PLUGIN Gallery

CVE-2024-11501

HIGH CVSS 8.8 2024-12-07
Threat Entry Updated 2026-06-17

Gallery - Cross-Site Scripting (XSS) (CVE-2024-3899)

The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to perform Cross-Site Scripting attacks.

PLUGIN Gallery

CVE-2024-3899

MEDIUM CVSS 4.8 2024-09-11
Threat Entry Updated 2026-06-17

Gallery - SQL Injection (CVE-2024-35750)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

PLUGIN Gallery

CVE-2024-35750

HIGH CVSS 8.5 2024-06-08
Threat Entry Updated 2026-06-17

Gallery - Cross-Site Scripting (XSS) (CVE-2024-30550)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

PLUGIN Gallery

CVE-2024-30550

HIGH CVSS 7.1 2024-03-31
Threat Entry Updated 2026-06-17

Gallery - Cross-Site Scripting (XSS) (CVE-2024-31120)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Stored XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

PLUGIN Gallery

CVE-2024-31120

MEDIUM CVSS 6.5 2024-03-31
Threat Entry Updated 2026-06-17

Gallery - Security Vulnerability (CVE-2023-6742)

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1.8.7.1. This makes it possible for authenticated attackers, with contributor access and above, to modify galleries on other users' posts.

PLUGIN Gallery

CVE-2023-6742

MEDIUM CVSS 4.3 2024-01-11
Threat Entry Updated 2026-06-17

Gallery - SQL Injection (CVE-2023-0765)

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable.

PLUGIN Gallery

CVE-2023-0765

HIGH CVSS 8.8 2023-04-17
Threat Entry Updated 2026-06-17

Gallery - Security Vulnerability (CVE-2023-0764)

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.

PLUGIN Gallery

CVE-2023-0764

MEDIUM CVSS 5.4 2023-04-17
Threat Entry Updated 2026-06-17

Gallery - Cross-Site Scripting (XSS) (CVE-2022-2190)

The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

PLUGIN Gallery

CVE-2022-2190

MEDIUM CVSS 6.1 2022-10-31
Threat Entry Updated 2026-06-17

Gallery - Cross-Site Scripting (XSS) (CVE-2022-1946)

The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

PLUGIN Gallery

CVE-2022-1946

MEDIUM CVSS 6.1 2022-07-04