
ACF Photo Gallery Field Security & Risk Analysis
wordpress.org/plugins/navz-photo-galleryA lightweight extension of Advanced Custom Field (ACF) that adds Photo Gallery field to any post/pages on your WordPress website.
Is ACF Photo Gallery Field Safe to Use in 2026?
Generally Safe
Score 95/100ACF Photo Gallery Field has a strong security track record. Known vulnerabilities have been patched promptly.
The Navz Photo Gallery plugin, version 3.1, exhibits a generally good security posture based on the static analysis. The absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events is commendable, as is the complete lack of unescaped output and the consistent use of prepared statements for SQL queries. The presence of nonce and capability checks on entry points further reinforces this positive assessment. However, a significant concern arises from the single instance of the `unserialize` function, which, if improperly handled, can lead to Remote Code Execution vulnerabilities. While the taint analysis did not reveal any unsanitized flows, the potential for `unserialize` to be misused remains a notable risk.
The vulnerability history for this plugin is a mixed bag. While there are no currently unpatched CVEs, the presence of four past medium-severity vulnerabilities, including Cross-Site Scripting and authorization issues, indicates a pattern of past security weaknesses. The fact that the last vulnerability was in February 2026 (a future date, implying this is historical data from a system that might be misconfigured or showing future dated data) suggests that while issues have been addressed, the codebase has historically had areas prone to vulnerabilities. This historical context, combined with the `unserialize` function, warrants careful monitoring and a cautious approach.
In conclusion, Navz Photo Gallery 3.1 demonstrates strengths in common web application security practices like output escaping and prepared statements. The attack surface is well-protected with authentication checks on its entry points. Nevertheless, the presence of `unserialize` and the historical record of medium-severity vulnerabilities, particularly those related to authorization and XSS, prevent a perfect security score. Vigilance is advised, and thorough testing of any new releases is recommended.
Key Concerns
- Presence of unserialize function
- History of 4 medium severity CVEs
ACF Photo Gallery Field Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
ACF Photo Gallery Field <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Attachment Metadata Modification
ACF Photo Gallery Field <= 2.6 - Missing Authorization in apgf_update_donation
ACF Photo Gallery Field <= 1.9 - Authenticated (Subscriber+) Arbitrary Usermeta Update
ACF Photo Gallery Field <= 1.7.4 - Reflected Cross-Site Scripting
ACF Photo Gallery Field Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
ACF Photo Gallery Field Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
ACF Photo Gallery Field Maintenance & Trust
Maintenance Signals
Community Trust
ACF Photo Gallery Field Alternatives
Advanced Custom Fields: NextGen Gallery Custom Field
advanced-custom-fields-nextgen-gallery-custom-field
This plugin provides an extra field for the Advanced Custom Fields plugin to support the NextGEN Gallery plugin.
Advanced Gallery & Repeater Fields for ACF
advanced-gallery-repeater-fields-for-acf
Advanced ACF fields with built-in layouts. Works with free ACF! Gallery & Repeater fields with masonry, carousel, lightbox & more.
Advanced Custom Fields (ACF®)
advanced-custom-fields
ACF helps customize WordPress with powerful, professional and intuitive fields. Proudly powering over 2 million sites, WordPress developers love ACF.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Extended
acf-extended
All-in-one enhancement suite that improves WordPress & Advanced Custom Fields.
ACF Photo Gallery Field Developer Profile
4 plugins · 61K total installs
How We Detect ACF Photo Gallery Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/navz-photo-gallery/assets/js/acf-photo-gallery-field.js/wp-content/plugins/navz-photo-gallery/assets/css/acf-photo-gallery-field.css/wp-content/plugins/navz-photo-gallery/assets/js/acf-photo-gallery-field.jsnavz-photo-gallery/assets/js/acf-photo-gallery-field.js?ver=navz-photo-gallery/assets/css/acf-photo-gallery-field.css?ver=HTML / DOM Fingerprints
acf-photo-gallery-field<!-- ACF Photo Gallery Field --><!-- END ACF Photo Gallery Field -->data-namedata-typeapgf_show_donationapgf_nonce/wp-json/acf/v1/field/wp-json/acf/v1/fields/wp-json/acf/v1/field_group/wp-json/acf/v1/field_groups