Extension WordPress

Vulnérabilités Photo Gallery by Ays – Responsive Image Gallery

Cette page rassemble les failles publiées pour Photo Gallery by Ays – Responsive Image Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
1Critiques
10Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Photo Gallery by Ays – Responsive Image Gallery

10 fiches

CVE-2025-13685 Moyenne · 4,3
Photo Gallery by Ays – Responsive Image Gallery

Photo Gallery by Ays <= 6.4.8 – Cross-Site Request Forgery to Bulk Actions

The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function.…

Versions affectées

*-6.4.8

Correctif

6.4.9

Publication

01/12/2025

CVE-2025-57947 Moyenne · 6,4
Photo Gallery by Ays – Responsive Image Gallery

Photo Gallery by Ays <= 6.3.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Photo Gallery by Ays plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-6.3.8

Correctif

6.3.9

Publication

22/09/2025

CVE-2023-39917 Moyenne · 4,3
Photo Gallery by Ays – Responsive Image Gallery

Photo Gallery by Ays <= 5.2.6 – Cross-Site Request Forgery

The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.2.6. This is due to missing nonce validation in the /admin/partials/gallery-photo-gallery-admin-display.php file. This makes it possible for unauthenticated…

Versions affectées

*-5.2.6

Correctif

5.2.7

Publication

07/08/2023

CVE-2023-32107 Moyenne · 6,1
Photo Gallery by Ays – Responsive Image Gallery

Photo Gallery by Ays <= 5.1.3 – Reflected Cross-Site Scripting via ays_gpg_settings_tab

The Photo Gallery by Ays plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ays_gpg_settings_tab’ parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-5.1.3

Correctif

5.1.4

Publication

03/05/2023

Vulnérabilité Moyenne · 6,1
Photo Gallery by Ays – Responsive Image Gallery

Photo Gallery by Ays – Responsive Image Gallery <= 4.4.3 – Reflected Cross-Site Scripting

The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-4.4.3

Correctif

4.4.4

Publication

29/06/2021

CVE-2021-24462 Élevée · 7,2
Photo Gallery by Ays – Responsive Image Gallery

Photo Gallery by Ays – Responsive Image Gallery <= 4.4.3 – Authenticated Blind SQL Injections

The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results()…

Versions affectées

[*, 4.4.4)

Correctif

4.4.4

Publication

29/06/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités