← WordPress Vulnerabilities
WordPress security by component

Photo Gallery Slideshow & Masonry Tiled Gallery

Photo Gallery Slideshow & Masonry Tiled Gallery is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jan 03, 2025; the highest CVE/CNA score is 7.1.

Plugin slug: wp-responsive-photo-gallery

CVE-2024-12237: Photo Gallery Slideshow & Masonry Tiled Gallery: Server-side request forgery

Photo Gallery Slideshow & Masonry Tiled Gallery is affected by server-side request forgery. Exploitation requires at least subscriber-level access. The vulnerable server can be induced to make attacker-selected network requests.

PublishedJan 03, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 03, 2025 CVE-2024-12237
Photo Gallery Slideshow & Masonry Tiled Gallery: Server-side request forgery
Photo Gallery Slideshow & Masonry Tiled Gallery is affected by server-side request forgery. Exploitation requires at least subscriber-level access. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.3
NVDPending
Oct 19, 2024 CVE-2019-25218
Photo Gallery Slideshow & Masonry Tiled Gallery: SQL injection
Photo Gallery Slideshow & Masonry Tiled Gallery is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVD4.9
Sep 29, 2023 CVE-2023-41658
Wp Responsive Photo Gallery: Cross-site scripting
Wp Responsive Photo Gallery is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1