← WordPress Vulnerabilities
WordPress security by component

Photo Gallery by Ays

Photo Gallery by Ays is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Dec 02, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: gallery-photo-gallery

CVE-2025-13685: Photo Gallery by Ays: Cross-site request forgery

Photo Gallery by Ays is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedDec 02, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 02, 2025 CVE-2025-13685
Photo Gallery by Ays: Cross-site request forgery
Photo Gallery by Ays is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 21, 2025 CVE-2025-11973
简数采集器: Filesystem traversal
简数采集器 is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVDPending
Sep 22, 2025 CVE-2025-57947
Photo Gallery by Ays: Cross-site scripting
Photo Gallery by Ays is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Jul 09, 2024 CVE-2024-37442
Photo Gallery by Ays: Code execution
Photo Gallery by Ays is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE3.8
NVD5.5
Mar 27, 2024 CVE-2024-29919
Photo Gallery by Ays: Cross-site scripting
Photo Gallery by Ays is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Oct 03, 2023 CVE-2023-39917
Gallery Photo Gallery: Cross-site request forgery
Gallery Photo Gallery is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Aug 18, 2023 CVE-2023-32107
Gallery Photo Gallery: Cross-site scripting
Gallery Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Aug 22, 2019 CVE-2016-10921
Gallery Photo Gallery: SQL injection
Gallery Photo Gallery is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8