WordPress security by component
Image Photo Gallery Final Tiles Grid
Plugin description
Image Photo Gallery Final Tiles Grid creates image galleries with flexible tile-based layouts for displaying photographs in WordPress.
Image Photo Gallery Final Tiles Grid (final-tiles-grid-gallery-lite) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Aug 22, 2026; the highest published CVSS base score is 6.4.
Plugin slug:
final-tiles-grid-gallery-liteLatest vulnerability
CVE-2026-4559: Final Tiles Grid Gallery permits Contributor-level stored cross-site scripting
Image Photo Gallery Final Tiles Grid through 3.6.12 does not adequately sanitize and escape the delay shortcode attribute. A Contributor or higher can store script in page content, and the payload executes whenever a user opens the affected page.
| Safe version |
|
||
|---|---|---|---|
| Aug 22, 2026 |
CVE-2026-4559
Final Tiles Grid Gallery permits Contributor-level stored cross-site scripting
Image Photo Gallery Final Tiles Grid through 3.6.12 does not adequately sanitize and escape the delay shortcode attribute. A Contributor or higher can store script in page content, and the payload executes whenever a user opens the affected page.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 20, 2026 |
CVE-2026-27424
Image Photo Gallery Final Tiles Grid: A security weakness
Image Photo Gallery Final Tiles Grid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.6.11.
|
3.6.12 |
CVE4.3
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39510
Image Photo Gallery Final Tiles Grid: A security weakness
Image Photo Gallery Final Tiles Grid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.6.11.
|
3.6.12 |
CVE2.7
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25375
Image Photo Gallery Final Tiles Grid: A security weakness
Image Photo Gallery Final Tiles Grid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 21, 2025 |
CVE-2025-13693
Image Photo Gallery Final Tiles Grid: Cross-site scripting
Image Photo Gallery Final Tiles Grid is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Dec 19, 2025 |
CVE-2025-14455
Image Photo Gallery Final Tiles Grid: A security weakness
Image Photo Gallery Final Tiles Grid is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Feb 27, 2025 |
CVE-2024-6261
Image Photo Gallery Final Tiles Grid: Cross-site scripting
Image Photo Gallery Final Tiles Grid is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|