{"error":0,"message":null,"data":{"name":"Meow Gallery","plugin":"meow-gallery","link":"https:\/\/wordpress.org\/plugins\/meow-gallery\/","latest":"1789621260","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"3a08db028687926e9f6b12720e6720edbd96487fa8e93834acfa113c5d6f59e6","name":"Meow Gallery [meow-gallery] < 4.1.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24465","name":"CVE-2021-24465","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24465","description":"[en] The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulated in a way that could lead to data disclosure and arbitrary objects to be deserialized.","date":"2021-10-04"},{"id":"746b4c6f6896c6b062924364fe6d613ba0b47a9d","name":"WordPress Meow Gallery plugin <= 4.1.8 - SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/meow-gallery\/vulnerability\/wordpress-meow-gallery-plugin-4-1-8-sql-injection-sqli-vulnerability","description":"SQL Injection (SQLi) vulnerability discovered by apple502j in WordPress Meow Gallery plugin (versions <= 4.1.8).","date":"2021-09-02"},{"id":"7d73aaa86b3ebd8a43d5b895f54f0583b768681f","name":"Meow Gallery (+ Gallery Block) <= 4.1.8 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/meow-gallery\/meow-gallery-gallery-block-418-sql-injection","description":"The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulated in a way that could lead to data disclosure and arbitrary objects to be deserialized.","date":"2021-09-02"},{"id":"08dbe202-0136-4502-87e7-5e984dc27b16","name":"Meow Gallery &lt; 4.1.9 - Contributor+ SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/08dbe202-0136-4502-87e7-5e984dc27b16","description":"The plugin does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before using it in an SQL statement, leading to an authenticated SQL Injection issue. The injection also allows the returned values to be manipulated in a way that could lead to data disclosure and arbitrary objects to be deserialized.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"8.1","severity":"h","exploitable":"2.8","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"8.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"2.8","impact":"5.2"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"ab00ad7fa90c3c71067c604a1ab3d63c1634e54e27ddb0e89b8c7328819c1554","name":"Meow Gallery [meow-gallery] < 4.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4de4266409d9ce5d04c7eeb9f41ed70d5a027bf1","name":"Meow Gallery (+ Gallery Block) <= 4.1.9 - Missing Authorization to Arbitrary Options Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/meow-gallery\/meow-gallery-gallery-block-419-missing-authorization-to-arbitrary-options-update","description":"The Meow Gallery plugin for WordPress is vulnerable to Arbitrary Options Update via the REST API in versions up to, and including, 4.1.9. This makes it possible for unauthenticated attackers to modify otherwise restricted arbitrary site options. This can be leveraged to create new administrative user accounts.","date":"2021-09-02"}],"impact":[]},{"uuid":"b74e48dd279892d5af12258ba80e5a93461c56a09c3d16e0eb1d18bd1039d837","name":"Meow Gallery [meow-gallery] < 4.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6cd95445-22bd-4666-8cf3-7979bfa5422d","name":"Meow Gallery &lt; 4.2.0 - Unauthorised Arbitrary Options Update via REST API","link":"https:\/\/wpscan.com\/vulnerability\/6cd95445-22bd-4666-8cf3-7979bfa5422d","description":"The plugin does not properly check for capability in its REST API, allowing\r\n- Any authenticated user with the upload_file capability (such as author+) to call them in versions before 4.1.9\r\n- Any unauthenticated user to call them except the rest_all_settings endpoint, in 4.1.9\r\n\r\nOne endpoint in particular could be used to update arbitrary options as there is also no validation done to ensure that the option belong to the plugin (in v &lt; 4.1.6). As a result, attackers can update\r\n- arbitrary options from the blog, such the &#039;home&#039; which would redirect all users to another website in versions before 4.1.6\r\n- arbitrary options from the plugin since 4.1.6\r\n\r\nIn 4.2.0, other endpoints were also given proper authorisation checks.","date":null}],"impact":[]},{"uuid":"f683e2b296075eabc47f09088ab584fcf74e20465418891a14c6496dfa5bbaa1","name":"Meow Gallery [meow-gallery] < 5.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4386","name":"CVE-2024-4386","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4386","description":"[en] The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018data_atts\u2019 parameter in versions up to, and including, 5.1.3  due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-09"},{"id":"5dea89f4934bd101daed76f9772a3fbc173979a7","name":"Gallery Block (Meow Gallery) <= 5.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/meow-gallery\/gallery-block-meow-gallery-513-authenticated-contributor-stored-cross-site-scripting","description":"The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018data_atts\u2019 parameter in versions up to, and including, 5.1.3  due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-08"},{"id":"348e088e1f7d3fcff249467a58bd2e2f721f3695","name":"WordPress Meow Gallery Plugin <= 5.1.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/meow-gallery\/vulnerability\/wordpress-gallery-block-meow-gallery-plugin-5-1-3-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Meow Gallery Plugin <= 5.1.3 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Meow Gallery<\/p><p>Link: https:\/\/wordpress.org\/plugins\/meow-gallery\/#developers<\/p><p>Affected Version <= 5.1.3<\/p><p>Fixed in version 5.1.4 <\/p>","date":"2024-05-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3d4e3d455afa61b39a5905e40b7cfb3c818955bfb83e8e079df64b889c1f6a70","name":"Meow Gallery [meow-gallery] < 5.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-47449","name":"CVE-2025-47449","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-47449","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Stored XSS.This issue affects Meow Gallery: from n\/a through <= 5.2.7.","date":"2025-05-07"},{"id":"EUVD-2025-13862","name":"EUVD-2025-13862","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-13862","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Meow Gallery allows Stored XSS. This issue affects Meow Gallery: from n\/a through 5.2.7.","date":"2025-05-07"},{"id":"dfbed80e3ee3151f6dc7c1571ebbd5804679ab37","name":"WordPress Meow Gallery Plugin <= 5.2.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/meow-gallery\/vulnerability\/wordpress-meow-gallery-5-2-7-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Meow Gallery Plugin <= 5.2.7 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Meow Gallery<\/p><p>Fixed in version 5.2.8 <\/p><p>Affected Version <= 5.2.7<\/p><p>CVE: CVE-2025-47449<\/p>","date":"2025-05-07"},{"id":"11109b0d4268f142bae4ee6cc2cdcaddeee01eb6","name":"Meow Gallery <= 5.2.7 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/meow-gallery\/meow-gallery-527-authenticated-author-stored-cross-site-scripting","description":"The Meow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"00f383374bbf94dd1a183a04f4f3a43a500c7b47003a2b26517408ea899ee38c","name":"Meow Gallery [meow-gallery] < 5.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-32418","name":"CVE-2026-32418","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-32418","description":"[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Blind SQL Injection.This issue affects Meow Gallery: from n\/a through <= 5.4.4.","date":"2026-03-13"},{"id":"ec306ffb17bec289e34dcfad1dc0065dcae6ad22","name":"Meow Gallery <= 5.4.4 - Authenticated (Author+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/meow-gallery\/meow-gallery-544-authenticated-author-sql-injection","description":"The Meow Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-02-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"7.6","severity":"h","exploitable":"2.3","impact":"4.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"2.3","impact":"4.7"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"de0860c302eefad11036d559bab09e07a245bef303ce4ac285045bbedc2658fc","name":"Meow Gallery [meow-gallery] < 5.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1291","name":"CVE-2026-1291","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1291","description":"[en] The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint \/wp-json\/meow-gallery\/v1\/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above, to arbitrarily create or overwrite existing gallery shortcode records by supplying a user-controlled id value. The endpoint performs database update operations without verifying that the requesting user is authorized to modify the referenced gallery record or create their own.","date":"2026-06-13"},{"id":"69966fbc67090043a44926b704ec47bfb1d9a13f","name":"Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/meow-gallery\/meow-gallery-544-missing-authorization-to-authenticated-author-shortcode-creation","description":"The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint \/wp-json\/meow-gallery\/v1\/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above, to arbitrarily create or overwrite existing gallery shortcode records by supplying a user-controlled id value. The endpoint performs database update operations without verifying that the requesting user is authorized to modify the referenced gallery record or create their own.","date":"2026-06-12"},{"id":"EUVD-2026-36649","name":"EUVD-2026-36649","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-36649","description":"The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint \/wp-json\/meow-gallery\/v1\/save_shortcode in all versions up to, and including, 5.4.4 This makes it possible for authenticated attackers, with Author-level access and above, to arbitrarily create or overwrite existing gallery shortcode records by supplying a user-controlled id value. The endpoint performs database update operations without verifying that the requesting user is authorized to modify the referenced gallery record or create their own.","date":"2026-06-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"641f7cd062abb7b3af019c35b96e33737d96aeb1315ccae06b41107fa82eed43","name":"Meow Gallery [meow-gallery] < 5.5.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15386","name":"CVE-2026-15386","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15386","description":"[en] The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.","date":"2026-08-07"},{"id":"85fa8a9034cb7f87fbc5ac1201a16b001f13361d","name":"Meow Gallery <= 5.5.1 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/meow-gallery\/meow-gallery-551-authenticated-author-stored-cross-site-scripting","description":"The Meow Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-03"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1786948137"}