Vulnerabilities and security researches forphotoblocks-grid-gallery photoblocks-grid-gallery
Direction: ascendingJun 07, 2024
Gallery PhotoBlocks # CVE-2019-15829
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 30, 2019
- Research Description
- The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
- Affected versions
-
max 1.1.43.
- Status
-
vulnerable
Gallery PhotoBlocks # CVE-2022-37407
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 09, 2022
- Research Description
- Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
- Affected versions
-
max 1.2.7.
- Status
-
vulnerable
Gallery PhotoBlocks # CVE-2022-36292
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 23, 2022
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
- Affected versions
-
max 1.2.9.
- Status
-
vulnerable
Nov 15, 2024
Gallery PhotoBlocks # CVE-2022-4974
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 1.2.6.
- Status
-
vulnerable
Sep 05, 2025
Gallery PhotoBlocks # CVE-2025-58610
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 03, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks photoblocks-grid-gallery allows Stored XSS.This issue affects Gallery PhotoBlocks: from n/a through <= 1.3.1.
- Affected versions
-
max 1.3.2.
- Status
-
vulnerable
Jan 27, 2026
Gallery PhotoBlocks # CVE-2026-24389
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 22, 2026
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks photoblocks-grid-gallery allows DOM-Based XSS.This issue affects Gallery PhotoBlocks: from n/a through <= 1.3.2.
- Affected versions
-
max 1.3.3.
- Status
-
vulnerable
Jun 16, 2026
Gallery PhotoBlocks # 9c464a1ba2ab5f94c0471cccd9243032c424be40
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 05, 2019
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.1.41 WordPress Gallery Photoblocks plugin <= 1.1.40 - Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Gallery Photoblocks plugin (versions <= 1.1.40).
- Affected versions
-
max 1.1.41.
- Status
-
vulnerable
Gallery PhotoBlocks # 17211923e33c5fb97c001eac7bb85516d0da4ff0
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 29, 2020
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.0 Gallery PhotoBlocks <= 1.1.5 - Cross-Site Scripting The Gallery PhotoBlocks plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.5 via several parameters due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected versions
-
max 1.2.0.
- Status
-
vulnerable
Gallery PhotoBlocks # 811416dc9e37c5314ae1e885f7f21dbd7389afa1
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 05, 2019
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.1.41 Gallery Photoblocks <= 1.1.40 - Reflected Cross-Site Scripting The Gallery Photoblocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the GET 'id' parameter in versions up to, and including, 1.1.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.1.41.
- Status
-
vulnerable
Gallery PhotoBlocks # a68496ed-67d3-4761-8f1f-d64424bec529
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.0 Gallery PhotoBlocks < 1.2.0 - Authenticated Cross-Site Scripting (XSS) The vulnerability is due to insufficient validation of gallery name parameter and image caption parameter. A remote attacker (any authenticated low privileged user) can exploit this to execute arbitrary script code within the context of the application.
- Affected versions
-
max 1.2.0.
- Status
-
vulnerable
Gallery PhotoBlocks # 8ac7de215e794d59ad6edfaaf75efeddefaa96b8
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2022
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.6 WordPress Gallery PhotoBlocks plugin <= 1.2.4 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Gallery PhotoBlocks plugin (versions <= 1.2.4).
- Affected versions
-
max 1.2.6.
- Status
-
vulnerable
Gallery PhotoBlocks # e558cea6e723531a53e25ce9904cdc813839d85b
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2022
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.6 WordPress Gallery PhotoBlocks plugin <= 1.2.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Gallery PhotoBlocks plugin (versions <= 1.2.4).
- Affected versions
-
max 1.2.6.
- Status
-
vulnerable
Gallery PhotoBlocks # 2aa811bbc4f4c73d078df9224626354e7a6f5529
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 10, 2019
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.1.43 WordPress Gallery Photoblocks plugin <= 1.1.42 - Authenticated Cross-Site Scripting (XSS) vulnerability Authenticated Cross-Site Scripting (XSS) vulnerability found in WordPress Gallery Photoblocks plugin (versions <= 1.1.42).
- Affected versions
-
max 1.1.43.
- Status
-
vulnerable
Gallery PhotoBlocks # 5c57e78a-97b9-4e23-8935-e4c9d806c89d
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.1.41 Gallery Photoblocks < 1.1.41 - Unauthenticated Reflected XSS Also Full Path Disclosure depending on the configuration of the server
- Affected versions
-
max 1.1.41.
- Status
-
vulnerable
Gallery PhotoBlocks # 49a2c22c842d21090919f915e007d58f37281c95
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 17, 2022
- Research Description
- Gallery PhotoBlocks [photoblocks-grid-gallery] < 1.2.9 Gallery PhotoBlocks <= 1.2.8 - Missing Authorization Checks The Gallery PhotoBlocks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.2.8 due to missing capability checks on the init() function found in the ~/admin/class-photoblocks-admin.php file. This makes it possible for authenticated users with minimal permissions, such as a subscriber, to delete and clone gallery photoblocks.
- Affected versions
-
max 1.2.9.
- Status
-
vulnerable
Jul 31, 2026
Gallery PhotoBlocks # CVE-2026-66448
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 27, 2026
- Research Description
- Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
- Affected versions
-
max 1.3.4.
- Status
-
vulnerable
Sep 04, 2026
Gallery PhotoBlocks # CVE-2026-84781
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 02, 2026
- Research Description
- Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.
- Affected versions
-
max 1.3.5.
- Status
-
vulnerable