CVE-2024-13906
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress
Minimum safe version
4.7.4
Update to 4.7.4 or later to address 12 fixable vulnerabilities
Gallery 3.06 - Unauthenticated File Upload PHP Code Execution
CVE-2023-0765
CVE-2023-0764
WordPress Gallery Plugin <= 4.6.9 is vulnerable to Cross Site Scripting (XSS)
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.6.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress < 4.5.0 - Reflected Cross-Site Scripting
Multiple BestWebSoft Plugins - Authenticated Cross-Site Scripting (XSS)
WordPress Gallery Plugin <= 3.8.3 - Arbitrary File Access
WordPress Gallery Plugin - Remote Arbitrary File Access
WordPress Gallery Plugin 3.06 - Arbitrary File Upload
CVE-2017-2171