
ImagePress – Image Gallery Security & Risk Analysis
wordpress.org/plugins/image-galleryA simple, multi-user WordPress plugin with a list of advanced options for creating beautiful, responsive image gallery plugin with front-end upload.
Is ImagePress – Image Gallery Safe to Use in 2026?
Generally Safe
Score 98/100ImagePress – Image Gallery has a strong security track record. Known vulnerabilities have been patched promptly.
The image-gallery plugin v1.3.1 exhibits a mixed security posture. On the positive side, the code analysis shows a strong adherence to secure coding practices, with no dangerous functions, no raw SQL queries, and a very high percentage of properly escaped output. The absence of file operations and external HTTP requests further reduces the attack surface. Additionally, the plugin has no currently unpatched CVEs, indicating good maintenance and responsiveness to past security issues.
However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers that lack authentication checks, presenting a direct vulnerability for unauthorized actions. While the taint analysis did not reveal any immediate critical or high-severity issues, the presence of unsanitized flows could still lead to vulnerabilities if exploited in conjunction with other weaknesses. The plugin's history of medium-severity vulnerabilities, including XSS, CSRF, and missing authorization, coupled with the current lack of authorization checks on AJAX handlers, suggests a recurring pattern of insecure input handling and access control, even though past issues are patched.
In conclusion, while the plugin demonstrates good practices in many areas, the unprotected AJAX handlers represent a critical security flaw that needs immediate attention. The history of past vulnerabilities, even if patched, warrants continued vigilance and thorough auditing of any new code. The plugin's strengths lie in its SQL handling and output escaping, but its weaknesses are concentrated in its access control mechanisms.
Key Concerns
- AJAX handlers without auth checks
- History of medium severity vulnerabilities
ImagePress – Image Gallery Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
ImagePress - Image Gallery <= 1.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings
ImagePress – Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update
ImagePress - Image Gallery <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Post Title Update
ImagePress – Image Gallery Code Analysis
Output Escaping
Data Flow Analysis
ImagePress – Image Gallery Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
ImagePress – Image Gallery Maintenance & Trust
Maintenance Signals
Community Trust
ImagePress – Image Gallery Alternatives
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
photo-gallery
Photo Gallery is a powerful image gallery plugin with a list of advanced options for creating responsive image galleries with beautiful lightbox.
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More
envira-gallery-lite
Envira Gallery is a fast, easy and powerful gallery builder with lightbox, masonry and grid layouts, albums, videos, and responsive displays and more
Gallery by FooGallery
foogallery
Photo Gallery, Image Gallery by FooGallery — fast, responsive, SEO-optimized, and packed with beautiful layouts.
Robo Gallery – Photo & Image Slider
robo-gallery
Robo Gallery is a powerful image gallery and photo gallery plugin with advanced features to create responsive galleries with a beautiful lightbox
ImagePress – Image Gallery Developer Profile
8 plugins · 4K total installs
How We Detect ImagePress – Image Gallery
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/image-gallery/css/admin/css/imagepress-admin.css/wp-content/plugins/image-gallery/css/admin/css/imagepress-admin-rtl.css/wp-content/plugins/image-gallery/css/frontend/css/imagepress-frontend.css/wp-content/plugins/image-gallery/css/frontend/css/imagepress-frontend-rtl.css/wp-content/plugins/image-gallery/css/frontend/css/imagepress-responsive.css/wp-content/plugins/image-gallery/js/admin/js/imagepress-admin.js/wp-content/plugins/image-gallery/js/frontend/js/imagepress-frontend.jsHTML / DOM Fingerprints
imagepress-gallery-containerImage Gallery (c) 2016-2025 Ciprian Popescu (https://getbutterfly.com/)data-ip-iddata-ip-typedata-ip-galleryimagepress_gallery_obj<div class="imagepress-gallery-container">