cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpicture-gallery picture-gallery

Direction: descending
May 12, 2026

Picture Gallery – Frontend Image Uploads, AJAX Photo List # CVE-2021-47951

CVE, Research URL

CVE-2021-47951

Date
May 10, 2026
Research Description
WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access Control settings. Attackers can enter JavaScript payloads in the plugin options that are stored in the database and executed when the functionality is triggered, enabling session hijacking or credential theft.
Affected versions
max 1.4.2.
Status
vulnerable
Mar 19, 2025

Picture Gallery – Frontend Image Uploads, AJAX Photo List # CVE-2025-26581

CVE, Research URL

CVE-2025-26581

Date
Mar 26, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Picture Gallery allows Reflected XSS. This issue affects Picture Gallery: from n/a through 1.6.2.
Affected versions
max 1.6.3.
Status
vulnerable
Jan 23, 2025

Picture Gallery – Frontend Image Uploads, AJAX Photo List # CVE-2024-13584

CVE, Research URL

CVE-2024-13584

Date
Jan 22, 2025
Research Description
The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode in all versions up to, and including, 1.5.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.5.20.
Status
vulnerable
Jan 19, 2025

Picture Gallery – Frontend Image Uploads, AJAX Photo List # CVE-2024-12696

CVE, Research URL

CVE-2024-12696

Date
Jan 18, 2025
Research Description
The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videowhisper_picture_upload_guest shortcode in all versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.5.23.
Status
vulnerable
Jun 07, 2024

Picture Gallery – Frontend Image Uploads, AJAX Photo List # 44813c6b4807acca8bf67f72f4e19949efc7c4a2

Date
Aug 06, 2021
Research Description
Picture Gallery &#8211; Frontend Image Uploads, AJAX Photo List [picture-gallery] < 1.4.4 WordPress Picture Gallery plugin <= 1.4.3 - Stored Cross-Site Scripting (XSS) vulnerability Stored Cross-Site Scripting (XSS) vulnerability discovered by Aryan Chehreghani in WordPress Picture Gallery plugin (versions <= 1.4.3).
Affected versions
max 1.4.4.
Status
vulnerable

Picture Gallery &#8211; Frontend Image Uploads, AJAX Photo List # CVE-2024-34759

CVE, Research URL

CVE-2024-34759

Date
Jun 05, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhisper Picture Gallery allows Stored XSS.This issue affects Picture Gallery: from n/a through 1.5.11.
Affected versions
max 1.5.12.
Status
vulnerable