CVE-2026-39510
Image Photo Gallery Final Tiles Grid
Minimum safe version
3.6.12
Update to 3.6.12 or later to address 17 fixable vulnerabilities
CVE-2026-25375
CVE-2025-15466
CVE-2025-14455
CVE-2025-13693
WordPress Image Photo Gallery Final Tiles Grid Plugin <= 3.6.0 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Image Photo Gallery Final Tiles Grid Plugin < 3.6.0 is vulnerable to Cross Site Scripting (XSS)
WordPress Image Photo Gallery Final Tiles Grid Plugin <= 3.5.6 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.3.52 - Authenticated Option Update vulnerability (Fremius Library security issue)
WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.5.4 - Sensitive Information Disclosure vulnerability
WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.5.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2020-14962
CVE-2022-0186