Extension WordPress

Vulnérabilités Image Photo Gallery Final Tiles Grid

Cette page rassemble les failles publiées pour Image Photo Gallery Final Tiles Grid, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
12Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Image Photo Gallery Final Tiles Grid

12 fiches

CVE-2026-39510 Moyenne · 4,3
Image Photo Gallery Final Tiles Grid

Image Photo Gallery Final Tiles Grid <= 3.6.11 – Authenticated (Author+) Insecure Direct Object Reference

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.6.11 due to missing validation on a user controlled key. This makes it possible…

Versions affectées

*-3.6.11

Correctif

3.6.12

Publication

11/02/2026

CVE-2025-15466 Moyenne · 5,4
Image Photo Gallery Final Tiles Grid

Image Photo Gallery Final Tiles Grid <= 3.6.9 – Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple AJAX actions in all versions up to, and including, 3.6.9. This makes…

Versions affectées

*-3.6.9

Correctif

3.6.10

Publication

19/01/2026

CVE-2025-13693 Moyenne · 6,4
Image Photo Gallery Final Tiles Grid

Image Photo Gallery Final Tiles Grid <= 3.6.8 – Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom scripts' setting in all versions up to, and including, 3.6.8 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-3.6.8

Correctif

3.6.9

Publication

20/12/2025

CVE-2025-14455 Moyenne · 5,4
Image Photo Gallery Final Tiles Grid

Image Photo Gallery Final Tiles Grid <= 3.6.7 – Missing Authorization to Authenticated (Contributor+) Gallery Management

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is due to the plugin not properly verifying that a user is authorized to…

Versions affectées

*-3.6.7

Correctif

3.6.8

Publication

18/12/2025

CVE-2024-6261 Moyenne · 6,4
Image Photo Gallery Final Tiles Grid

Image Photo Gallery Final Tiles Grid <= 3.6.0 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'FinalTilesGallery' shortcode in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on…

Versions affectées

*-3.6.0

Correctif

3.6.1

Publication

26/02/2025

CVE-2024-3710 Moyenne · 6,4
Image Photo Gallery Final Tiles Grid

Image Photo Gallery Final Tiles Grid <= 2.5.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Additional CSS class on A tag" field in all versions up to, and including, 2.5.8 due to insufficient input sanitization…

Versions affectées

*-2.5.8

Correctif

3.6.0

Publication

22/06/2024

Vulnérabilité Élevée · 8,8
Image Photo Gallery Final Tiles Grid

Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

[*, 3.3.57)

Correctif

3.3.57

Publication

25/02/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités