CVE-2026-81653: Photo Gallery, Sliders, Proofing and Themes
- Severity
- 0 (N/A)
- Affected versions
- 0 through before 4.5.0
- Fixed version
- 4.5.0
- Patch status
- Patched
- Published
- 2026-09-20T07:16:49.900
- Modified
- 2026-09-20T07:16:49.900
Why it matters
This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.
Recommended admin actions
- Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
- Check whether the affected WordPress plugin or theme is installed.
- Update, disable, or remove the affected component if present.
- Compare installed versions against the affected version range in the advisory.
Technical summary
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging to other users.
View the official NVD record for CVE-2026-81653
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-78030 |
DBI PATCH
Reporter: 9B29ABF9-4AB0-4765-B253-1875CD9B441E
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-93985 |
openpanel
Reporter: DISCLOSURE
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-94083 |
Product identification pending PATCH
Reporter: CVE
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-94084 |
Product identification pending PATCH
Reporter: CVE
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-4327 |
The Welcomizer
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-93990 |
libexpat
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-93742 |
A3002MU
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-93993 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-93958 |
R95
Reporter: CNA
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-86553 |
Product identification pending
Reporter: PSIRT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-93991 |
Product identification pending
Reporter: DISCLOSURE
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-85658 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-1255 |
YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-94056 |
Product identification pending PATCH
Reporter: CVE
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-15664 |
Quill Forms | Conversational Multi Step Forms, Surveys & quizzes
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93988 |
Product identification pending
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-93992 |
Product identification pending
Reporter: DISCLOSURE
|
7
HIGH
|
VIEW RECORD |
| CVE-2026-94054 |
Product identification pending PATCH
Reporter: CVE
|
7
HIGH
|
VIEW RECORD |
| CVE-2026-93984 |
openpanel
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93961 |
UJCMS
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93969 |
SxDevOps
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-94000 |
Product identification pending
Reporter: SECALERT
|
6.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-13191 |
Create
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-13200 |
Create
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-1641 |
Wow Elements Addons for Elementor
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-9232 |
Easy Appointments
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-9855 |
Custom Field Template
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94001 |
Product identification pending
Reporter: SECALERT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-13770 |
AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-15098 |
Real3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-2422 |
WP Composer – The Easiest Page Builder
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-5400 |
Redux Framework
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-1256 |
YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-5410 |
Redux Framework
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-8354 |
Gum Addon for Elementor
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-82672 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-11608 |
WP Customer Reviews
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-15463 |
SSL Zen — SSL Certificate Installer & HTTPS Redirects
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-87917 |
MC4WP: Mailchimp for WordPress
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93959 |
Online Reviewer Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93962 |
Kamailio PATCH
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93964 |
nginx-proxy-manager
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-1984 |
Ibtana – Ecommerce Product Addons
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-4792 |
Bread
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-9832 |
Payment Gateway of Stripe for WooCommerce
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-18346 |
TikTok
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-9289 |
WordLift – AI powered SEO – Schema
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-93983 |
openpanel
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-93965 |
SxDevOps
Reporter: CNA
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93966 |
SxDevOps
Reporter: CNA
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93967 |
SxDevOps
Reporter: CNA
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93968 |
SxDevOps
Reporter: CNA
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-6295 |
WP Optimizer – PageSpeed, Cache, Minify & Core Web Vitals
Reporter: SECURITY
|
4.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-75959 |
GoPay for WooCommerce
Reporter: SECURITY
|
4.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93982 |
openpanel
Reporter: DISCLOSURE
|
4.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-7527 |
Hide My WP Ghost – Security & Firewall
Reporter: SECURITY
|
4.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-76579 |
LiteSpeed Cache
Reporter: SECURITY
|
4.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-93987 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
4.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-12402 |
OTP Login & Register Woocommerce
Reporter: SECURITY
|
4.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-11899 |
PDF Builder for WooCommerce. Create invoices,packing slips and more
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-15946 |
Search Atlas SEO – OTTO AI SEO Automation for WordPress
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-15947 |
Search Atlas SEO – OTTO AI SEO Automation for WordPress
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-1242 |
BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-2278 |
VW Writer Blog
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-9615 |
Flex Import
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-9613 |
Datalogics Ecommerce Delivery – Datalogics
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-9766 |
Empik for Woocommerce
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-9858 |
Partial Shipment for WooCommerce
Reporter: SECURITY
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86552 |
Product identification pending
Reporter: PSIRT
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-93999 |
Product identification pending
Reporter: SECALERT
|
4.2
MEDIUM
|
VIEW RECORD |
| CVE-2026-94057 |
Product identification pending PATCH
Reporter: CVE
|
4
MEDIUM
|
VIEW RECORD |
| CVE-2026-94055 |
Product identification pending PATCH
Reporter: CVE
|
3.7
LOW
|
VIEW RECORD |
| CVE-2026-86551 |
Product identification pending
Reporter: PSIRT
|
3.3
LOW
|
VIEW RECORD |
| CVE-2026-93981 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
2.3
LOW
|
VIEW RECORD |
| CVE-2026-93986 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
2.3
LOW
|
VIEW RECORD |
| CVE-2026-93989 |
Product identification pending
Reporter: DISCLOSURE
|
2.3
LOW
|
VIEW RECORD |
| CVE-2026-93954 |
grimmory
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-93955 |
grimmory
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-93957 |
PHP-FTS PATCH
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-93960 |
Pixelfed PATCH
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-93963 |
Leave Management System
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-93956 |
PHP-FTS PATCH
Reporter: CNA
|
2
LOW
|
VIEW RECORD |
| CVE-2026-82560 |
Product identification pending PATCH
Reporter: 9B29ABF9-4AB0-4765-B253-1875CD9B441E
|
0
N/A
|
VIEW RECORD |
| CVE-2026-14844 |
Master Slider
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-16542 |
Import and export users and customers PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-81650 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-81651 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-81652 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-81653 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-81654 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-82842 |
SAML Single Sign On PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-84223 |
Kirki PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-85017 |
Unlimited Elements For Elementor PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-87067 |
Forminator Forms PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-87068 |
Forminator Forms PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-87839 |
Tripzzy PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-87840 |
Tripzzy PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-92410 |
Sign-up Sheets PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-92422 |
Meow Gallery PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
| CVE-2026-92423 |
Meow Gallery PATCH
Reporter: CONTACT
|
0
N/A
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.