Enviragallery maintains a gallery and media-management plugin that, despite narrow product scope, occupies a notable position in the WordPress ecosystem where it serves a wide deployment base. The vulnerability profile concentrates in the Envira Gallery plugin and recurs through web-application weakness classes including cross-site scripting in page generation, missing authorization checks, and improper handling of exceptional conditions—characteristic of plugins that process user-supplied content and manage access controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enviragallery over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43925HIGH Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envira Ph | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-2190MEDIUM The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflecte | Oct 31, 2022 | 6.1 | 22 | NO | NO |
CVE-2020-35582MEDIUM A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/post.php reque | Jan 15, 2021 | 5.4 | 20 | NO | NO |
CVE-2020-35581MEDIUM A stored cross-site scripting (XSS) issue in Envira Gallery Lite before 1.8.3.3 allows remote attackers to inject arbitrary JavaScript/HTML code via a POST /wp-admin/admin-ajax.php | Jan 15, 2021 | 5.4 | 20 | NO | NO |
CVE-2020-9334MEDIUM A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-priv | Feb 25, 2020 | 5.4 | 20 | NO | NO |
CVE-2021-24126MEDIUM Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) bef | Mar 18, 2021 | 5.4 | 19 | NO | NO |
CVE-2024-3899MEDIUM The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such a | Sep 11, 2024 | 4.8 | 16 | NO | NO |
CVE-2023-6742MEDIUM The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_g | Jan 11, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enviragallery.
Media articles that mention a CVE ID that affects a product developed by Enviragallery — matched by CVE ID, not by vendor name.