Medium 6.4 Unfixed
2026-05-10≤ 1.4.2
CVE-2021-47951
Minimum safe version
1.6.4
Update to 1.6.4 or later to address 7 fixable vulnerabilities
CVE-2021-47951
CVE-2025-26581
CVE-2024-13584
CVE-2024-12696
CVE-2024-34759
Picture Gallery < 1.4.4 - Authenticated Stored XSS
Picture Gallery – Frontend Image Uploads, AJAX Photo List < 1.4.3 - Cross-Site Scripting
WordPress Picture Gallery plugin <= 1.4.3 - Stored Cross-Site Scripting (XSS) vulnerability