
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Security & Risk Analysis
wordpress.org/plugins/envira-gallery-liteEnvira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Is Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Safe to Use in 2026?
Generally Safe
Score 95/100Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "envira-gallery-lite" v1.12.4 exhibits a mixed security posture. While it demonstrates several good security practices, such as using prepared statements for all SQL queries and a high percentage of properly escaped output, there are significant areas of concern. The presence of one AJAX handler without authentication checks is a critical vulnerability that could allow unauthorized actions. Furthermore, the taint analysis revealed four flows with unsanitized paths, indicating potential for various injection vulnerabilities, although these are not classified as critical or high severity in this analysis. The plugin's vulnerability history is a major red flag, with a total of 10 known medium severity CVEs, including past instances of CSRF, Missing Authorization, and Cross-site Scripting. The fact that these are currently unpatched, despite the last vulnerability being reported in 2026, suggests a lack of timely security patching and a history of introducing exploitable flaws.
In conclusion, while the static code analysis highlights some positive security implementations, the combination of an unprotected entry point, unsanitized paths in taint flows, and a substantial history of medium-severity vulnerabilities, especially those related to authorization and input sanitization, presents a notable risk. The absence of currently unpatched critical or high vulnerabilities is a slight positive, but the recurring nature of medium vulnerabilities and the identified unprotected AJAX handler warrant careful consideration and immediate attention. The plugin's strengths lie in its SQL handling and output escaping, but its weaknesses in authorization and input validation, as evidenced by both static analysis and historical data, outweigh these benefits in the current assessment.
Key Concerns
- AJAX handler without auth checks
- Flows with unsanitized paths found
- 10 medium severity CVEs historically
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Envira Gallery for WordPress <= 1.12.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API
Gallery Plugin for WordPress – Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions
Gallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion
Envira Photo Gallery <= 1.8.14 - Missing Authorization
Gallery Plugin for WordPress – Envira Photo Gallery <= 1.8.14 - Authenticated (Author+) Stored Cross-Site Scripting
Envira Photo Gallery <= 1.8.7.3 - Cross-Site Request Forgery to Notice Dismissal
Envira Gallery Lite <= 1.8.7.2 - Missing Authorization to Gallery Modification via envira_gallery_insert_images
Gallery Plugin for WordPress – Envira Photo Gallery <= 1.8.4.6 - Reflected Cross-Site Scripting
Envira Gallery Lite <= 1.8.3.2 - Cross-Site Scripting
Envira Photo Gallery <= 1.7.6 - Authenticated Stored Cross-Site Scripting
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Attack Surface
AJAX Handlers 30
REST API Routes 3
Shortcodes 1
WordPress Hooks 111
Scheduled Events 2
Maintenance & Trust
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Maintenance & Trust
Maintenance Signals
Community Trust
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Alternatives
Gmedia Photo Gallery
grand-media
Gmedia Gallery - photo gallery with comments, show EXIF & Metadata, gallery with map geolocation (GPS), private galleries.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery
gt3-photo-video-gallery
GT3 Image Gallery - create photo gallery, video gallery, block gallery, slider and more with ease. All photo galleries are responsive and loading fast
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More Developer Profile
94 plugins · 23.5M total installs
How We Detect Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envira-gallery-lite/assets/css/envira-gallery.css/wp-content/plugins/envira-gallery-lite/assets/js/envira-gallery.jsEnvira Gallery - Image Photo Gallery, Albums, Video Gallery, Slideshows & More 1.12.4/wp-content/plugins/envira-gallery-lite/assets/js/envira-gallery.jsenvira-gallery-lite/assets/css/envira-gallery.css?ver=envira-gallery-lite/assets/js/envira-gallery.js?ver=HTML / DOM Fingerprints
envira-gallery-litedata-envira-gallery-idenvira_gallery_lite/wp-json/envira-gallery-lite/v1[envira-gallery