smub Vulnerabilities and Affected Products
Vulnerabilities associated with Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery.
Products
Clear product- Easy Digital Downloads – eCommerce Payments and Subscriptions made easy15 vulnerabilities
- Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More8 vulnerabilities
- All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic7 vulnerabilities
- Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery7 vulnerabilities
- Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More6 vulnerabilities
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More6 vulnerabilities
- Sydney Toolbox5 vulnerabilities
- aThemes Addons for Elementor4 vulnerabilities
- ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)4 vulnerabilities
- Custom Twitter Feeds – A Tweets Widget or X Feed Widget3 vulnerabilities
- Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers3 vulnerabilities
- Smash Balloon Social Photo Feed – Easy Social Feeds Plugin3 vulnerabilities
- UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds3 vulnerabilities
- Contact Form & SMTP Plugin for WordPress by PirateForms2 vulnerabilities
- Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more2 vulnerabilities
- Feeds for YouTube (YouTube video, channel, and gallery plugin)2 vulnerabilities
- Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More2 vulnerabilities
- WP Mail Logging2 vulnerabilities
- WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More2 vulnerabilities
- aThemes Starter Sites1 vulnerability
- Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More1 vulnerability
- PDF Embedder1 vulnerability
- Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation1 vulnerability
- Slider by Soliloquy – Responsive Image Slider for WordPress1 vulnerability
- Smash Balloon Social Post Feed – Simple Social Feeds for WordPress1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-6566MEDIUM | Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST APIThe Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DELETE /imagely/v1/images/{id} only checks 'NextGEN Manage gallery' permissions and does not enforce gallery ownership or 'NextGEN Manage others gallery' permissions. This makes it possible for authentic… CWE-639May 20, 2026 | CVSS4.3v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1463HIGH | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File InclusionThe Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve… CWE-98Mar 18, 2026 | CVSS8.8v3.1 | EPSS0.452% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13641HIGH | Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 3.59.12 - Authenticated (Contributor+) Local File Inclusion via 'template'The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.59.12 via the 'template' shortcode parameter. This is due to insufficient path validation that allows absolute paths to be provided. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server, bypassing web server restrictions like .htaccess. S… | CVSS8.8v3.1 | EPSS0.735% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-2537MEDIUM | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript LibraryMultiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScript library (version 3.1) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Jul 3, 2025 | CVSS6.4v3.1 | EPSS0.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5878MEDIUM | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript LibraryMultiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox JavaScript library (version 2.1.5) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79May 20, 2025 | CVSS6.4v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5020MEDIUM | Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript LibraryMultiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Dec 4, 2024 | CVSS6.4v3.1 | EPSS0.421% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3097MEDIUM | WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information DisclosureThe WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin. | CVSS5.3v3.1 | EPSS38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |