Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total8
Critical1
High5
Medium2
Reset
Showing 1-8 of 8 records
Threat Entry Updated 2025-03-01

CVE-2024-13833 - Wordpress Gallery Plugin

The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or…

PLUGIN Wordpress Gallery

CVE-2024-13833

HIGH CVSS 7.2 2025-03-01
Threat Entry Updated 2025-01-16

CVE-2025-23842 - WordPress Gallery Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Nilesh Shiragave WordPress Gallery Plugin allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin: from n/a through 1.4.

PLUGIN WordPress Gallery Plugin

CVE-2025-23842

HIGH CVSS 7.1 2025-01-16
Threat Entry Updated 2024-10-07

CVE-2024-9018 - Wordpress Gallery Plugin

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wordpress Gallery

CVE-2024-9018

HIGH CVSS 8.8 2024-10-01
Threat Entry Updated 2025-09-26

CVE-2024-8436 - Wordpress Gallery Plugin

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN Wordpress Gallery

CVE-2024-8436

CRITICAL CVSS 9.9 2024-09-25
Threat Entry Updated 2025-05-29

CVE-2024-8437 - Wordpress Gallery Plugin

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and including, 4.8.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify galleries.

PLUGIN Wordpress Gallery

CVE-2024-8437

MEDIUM CVSS 4.3 2024-09-25
Threat Entry Updated 2024-11-21

CVE-2023-3154 - Wordpress Gallery Plugin

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

PLUGIN Wordpress Gallery

CVE-2023-3154

HIGH CVSS 7.5 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-3155 - Wordpress Gallery Plugin

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

PLUGIN Wordpress Gallery

CVE-2023-3155

HIGH CVSS 7.2 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-3279 - Wordpress Gallery Plugin

The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks

PLUGIN Wordpress Gallery

CVE-2023-3279

MEDIUM CVSS 4.9 2023-10-16
Scroll to top