Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-12-02

CVE-2025-13685 - Photo Gallery By Ays Plugin

The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for unauthenticated attackers to perform bulk operations (delete, publish, or unpublish galleries) via a forged request granted they can trick an administrator into performing an action such as clicking on a link.

PLUGIN Photo Gallery By Ays

CVE-2025-13685

MEDIUM CVSS 4.3 2025-12-02
Threat Entry Updated 2024-11-21

CVE-2023-2568 - Photo Gallery By Ays Plugin

The Photo Gallery by Ays WordPress plugin before 5.1.7 does not escape some parameters before outputting it back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Photo Gallery By Ays

CVE-2023-2568

MEDIUM CVSS 6.1 2023-06-12
Scroll to top