Extension WordPress
Vulnérabilités Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
Cette page rassemble les failles publiées pour Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
13 fiches
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More <= 1.12.5 – Missing Authorization
The Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.12.5. This…
*-1.12.5
1.12.6
15/06/2026
Envira Gallery <= 1.12.4 – Authenticated (Author+) Stored Cross-Site Scripting via 'arrows' Parameter
The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in the update_gallery_data() function and improper output…
*-1.12.4
1.12.5
13/05/2026
Envira Gallery for WordPress <= 1.12.3 – Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API
The Envira Gallery for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'justified_gallery_theme' parameter in all versions up to, and including, 1.12.3 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.12.3
1.12.4
03/03/2026
Gallery Plugin for WordPress – Envira Photo Gallery <= 1.12.0 – Missing Authorization to Authenticated (Author+) Multiple Gallery Actions
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.12.0. This makes…
*-1.12.0
1.12.1
12/11/2025
Gallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 – Missing Authorization to Authenticated (Contributor+) Gallery Conversion
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/envira-convert/v1/bulk-convert' REST API endpoint in all versions up to, and including,…
*-1.11.0
1.12.0
07/11/2025
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-1.8.15
1.8.16
03/12/2024
Envira Photo Gallery <= 1.8.14 – Missing Authorization
The Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the envira_gallery_ajax_load_gallery_data() function in versions up to, and including, 1.8.14. This makes it possible for authenticated attackers,…
*-1.8.14
1.8.15
26/08/2024
Gallery Plugin for WordPress – Envira Photo Gallery <= 1.8.14 – Authenticated (Author+) Stored Cross-Site Scripting
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery image title field in all versions up to, and including, 1.8.14 due to insufficient input sanitization and…
*-1.8.14
1.8.15
20/08/2024
Envira Photo Gallery <= 1.8.7.3 – Cross-Site Request Forgery to Notice Dismissal
The Envira Photo Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.7.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…
*-1.8.7.3
1.8.8
20/06/2024
Envira Gallery Lite <= 1.8.7.2 – Missing Authorization to Gallery Modification via envira_gallery_insert_images
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1.8.7.1. This…
*-1.8.7.2
1.8.7.3
08/01/2024
Gallery Plugin for WordPress – Envira Photo Gallery <= 1.8.4.6 – Reflected Cross-Site Scripting
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in versions up to, and including, 1.8.4.6 due to insufficient input sanitization and output escaping. This makes it…
[*, 1.8.4.7)
1.8.4.7
10/10/2022
Envira Gallery Lite <= 1.8.3.2 – Cross-Site Scripting
Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege…
[*, 1.8.3.3)
1.8.3.3
19/12/2020
Envira Photo Gallery <= 1.7.6 – Authenticated Stored Cross-Site Scripting
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
[*, 1.7.7)
1.7.7
25/02/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.