N/A
2026-03-03< 1.12.4
Envira Gallery for WordPress <= 1.12.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API
Minimum safe version
1.12.4
Update to 1.12.4 or later to address 12 fixable vulnerabilities
Envira Gallery for WordPress <= 1.12.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API
CVE-2025-12377
CVE-2025-11448
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
CVE-2024-3899
CVE-2024-43925
CVE-2024-37095
CVE-2023-6742
CVE-2022-2190
WordPress Envira Photo Gallery plugin <= 1.8.3.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2020-9334
CVE-2021-24126