Medium 4.3
2025-12-02< 6.4.9
CVE-2025-13685
Minimum safe version
6.4.9
Update to 6.4.9 or later to address 11 fixable vulnerabilities
CVE-2025-13685
WordPress Photo Gallery by Ays Plugin <= 6.3.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-37442
CVE-2024-29919
CVE-2023-39917
WordPress Photo Gallery by Ays Plugin < 5.1.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-32107
Photo Gallery by Ays – Responsive Image Gallery <= 4.4.3 - Reflected Cross-Site Scripting
Multiple Plugins from AYS Pro - Reflected Cross-Site Scripting (XSS)
CVE-2016-10921
CVE-2021-24462