Skip to content
Noroxi

Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More

envira-gallery-lite · plugin

Known security vulnerabilities for Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More. Find out in seconds which version runs on your site with WP Lens.

10 known vulnerabilities

latest Aug 28, 2026

Vulnerabilities

  • CVE-2024-43925

    WordPress Envira Gallery Lite plugin <= 1.8.14 - Broken Access Control vulnerability

    High 8.8
  • CVE-2026-54190

    WordPress Envira Photo Gallery plugin <= 1.12.5 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-3423

    Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description

    Medium 6.4
  • CVE-2026-5361

    Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via 'arrows' Parameter

    Medium 6.4
  • CVE-2026-1236

    Envira Gallery for WordPress <= 1.12.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API

    Medium 6.4
  • CVE-2020-9334

    A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress.

    Medium 5.4
  • CVE-2025-12377

    Gallery Plugin for WordPress – Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions

    Medium 4.3
  • CVE-2025-11448

    Gallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion

    Medium 4.3
  • CVE-2024-37095

    WordPress Envira Photo Gallery plugin <= 1.8.7.3 - CSRF leading to notice dismissal vulnerability

    Medium 4.3
  • CVE-2023-6742

    Envira Gallery Lite <= 1.8.7.2 - Missing Authorization to Gallery Modification via envira_gallery_insert_images

    Medium 4.3

← Back to directory