Medium 5.9 Unfixed 2025-09-22≤ 1.5.5 TZ PlusGallery <= 1.5.5 - Authenticated (Editor+) Stored Cross-Site Scripting WordfenceEUVDCVE
Medium 4.3 Unfixed 2025-04-01≤ 1.5.5 WordPress TZ PlusGallery Plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) vulnerability CVEPatchstackWordfenceEUVD