SimpLy Gallery Security & Risk Analysis

wordpress.org/plugins/simply-gallery-block

Create responsive photo, image, video, and mixed media galleries for WordPress with gallery blocks, albums, sliders, and a built-in lightbox.

40K active installs v3.3.3.3 PHP 7.4+ WP 6.8+ Updated Jun 22, 2026
galleryimage-gallerylightboxphoto-galleryvideo-gallery
89
A · Safe
CVEs total9
Unpatched0
Last CVEJul 10, 2026
Safety Verdict

Is SimpLy Gallery Safe to Use in 2026?

Generally Safe

Score 89/100

SimpLy Gallery has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

9 known CVEsLast CVE: Jul 10, 2026Updated 2mo ago
Risk Assessment

The "simply-gallery-block" plugin v3.3.2.3 presents a mixed security posture. On the positive side, the static analysis indicates a strong adherence to good security practices with all identified entry points (AJAX handlers, shortcodes) appearing to have proper authorization and nonce checks. The plugin also demonstrates excellent practices regarding SQL queries, exclusively using prepared statements, and a high percentage of output escaping. Furthermore, there are no critical or high severity issues identified in the taint analysis, and no unpatched vulnerabilities in its history.

However, several areas raise concern. The presence of a "Dangerous function" (preg_replace(/e)) warrants attention, as this can be a common vector for code injection if not handled with extreme care. While no unsanitized paths were found in the taint analysis, the historical vulnerability data reveals a significant pattern of medium severity issues, primarily related to Missing Authorization and Cross-site Scripting (XSS). The plugin has a history of 7 known CVEs, all of which are currently patched. The recurrence of these vulnerability types, even if patched, suggests potential areas in the codebase that require ongoing vigilance and rigorous code review.

In conclusion, while the current version shows good immediate security controls and no critical flaws, the historical trend of medium severity vulnerabilities, particularly XSS and authorization bypass, combined with the use of a potentially dangerous function, indicates that users should remain aware. The plugin's strengths lie in its SQL and output escaping practices, but past issues suggest a need for continued security auditing and development attention to prevent recurrence of past vulnerability types.

Key Concerns

  • Dangerous function: preg_replace(/e)
  • Bundled library: Freemius v1.0 (potentially outdated)
  • History of 7 CVEs (medium severity)
  • Common vulnerability types: Missing Auth, XSS
Vulnerabilities
9 published

SimpLy Gallery Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2023
2023
2 CVEs in 2024
2024
3 CVEs in 2025
2025
2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

High
2
Medium
7

9 total CVEs

CVE-2026-5743medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute

Jul 10, 2026 Patched in 3.3.3.2 (1d)
CVE-2026-25345high · 8.8Improper Control of Generation of Code ('Code Injection')

Mixed Media Gallery Blocks <= 3.3.2 - Authenticated (Contributor+) Remote Code Execution

Mar 23, 2026 Patched in 3.3.2.1 (44d)
CVE-2025-14288medium · 4.3Missing Authorization

Gallery Blocks with Lightbox <= 3.3.0 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification

Dec 12, 2025 Patched in 3.3.1 (1d)
CVE-2025-63052medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SimpLy Gallery <= 3.3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 26, 2025 Patched in 3.3.2.2 (132d)
CVE-2025-32176medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gallery Blocks with Lightbox <= 3.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 4, 2025 Patched in 3.2.6 (20d)
CVE-2024-10034medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.4.2 - Authenticated (Editor+) Stored Cross-Site Scripting

Nov 21, 2024 Patched in 3.2.4.3 (1d)
CVE-2024-5424medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters

Jun 27, 2024 Patched in 3.2.2 (1d)
CVE-2023-0441high · 8.1Missing Authorization

Gallery Blocks with Lightbox <= 3.0.7 - Missing Authorization in pgc_sgb_action_wizard

Mar 1, 2023 Patched in 3.0.8 (328d)
CVE-2021-24667medium · 5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Gallery Blocks with Lightbox <= 2.2.0 - Authenticated Stored Cross-Site Scripting

Aug 23, 2021 Patched in 2.2.1 (883d)
Version History

SimpLy Gallery Release Timeline

Code Analysis
Analyzed Mar 16, 2026

SimpLy Gallery Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
9
122 escaped
Nonce Checks
2
Capability Checks
22
File Operations
0
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

preg_replace(/e)preg_replace( '/eblocks\init.php:148

Bundled Libraries

Freemius1.0

Output Escaping

93% escaped131 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
pgc_sgb_galleries_permalink_settings_save (blocks\simply_post.php:620)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SimpLy Gallery Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 1

authwp_ajax_pgc_sgb_action_wizardplugin.php:969

Shortcodes 2

[pgc_simply_gallery] blocks\simply_post.php:522
[pgc_simply_album] blocks\simply_post.php:523
WordPress Hooks 32
actionelementor/widgets/widgets_registeredblocks\class-elementor.php:10
actionwp_headblocks\init.php:161
actioninitblocks\init.php:351
actioncustomize_preview_initblocks\init.php:352
actionadmin_enqueue_scriptsblocks\init.php:358
actionwp_dashboard_setupblocks\simply_dashboard_widget.php:52
actionadmin_enqueue_scriptsblocks\simply_dashboard_widget.php:53
filterthe_contentblocks\simply_post.php:43
filterallowed_block_typesblocks\simply_post.php:940
filterallowed_block_types_allblocks\simply_post.php:942
filteradmin_noticesblocks\simply_post.php:944
actionadmin_menublocks\simply_post.php:950
actionrest_api_initblocks\simply_post.php:951
actioninitblocks\simply_post.php:952
actionrestrict_manage_postsblocks\simply_post.php:953
actionadmin_enqueue_scriptsblocks\simply_post.php:954
actionadmin_initblocks\simply_post.php:955
actionadmin_initblocks\simply_post.php:956
actionwidgets_initblocks\simply_widget.php:92
actionafter_uninstallplugin.php:82
actionplugins_loadedplugin.php:88
actioninitplugin.php:165
actioninitplugin.php:304
actionwp_enqueue_scriptsplugin.php:339
actioninitplugin.php:465
actionadmin_menuplugins\init.php:166
actionadmin_menuplugins\init.php:221
actionadmin_menuplugins\init.php:273
actionadmin_menuplugins\init.php:323
actioninitplugins\init.php:324
actionenqueue_block_editor_assetsplugins\init.php:325
actionwp_enqueue_scriptsplugins\init.php:326
Maintenance & Trust

SimpLy Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 22, 2026
PHP min version7.4
Downloads1.2M

Community Trust

Rating96/100
Number of ratings116
Active installs40K
Developer Profile

SimpLy Gallery Developer Profile

GalleryCreator

1 plugin · 40K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
157 days
View full developer profile
Detection Fingerprints

How We Detect SimpLy Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simply-gallery-block/assets/css/frontend.css/wp-content/plugins/simply-gallery-block/assets/css/lightbox.css/wp-content/plugins/simply-gallery-block/assets/js/frontend.js/wp-content/plugins/simply-gallery-block/assets/js/lightbox.js/wp-content/plugins/simply-gallery-block/blocks/skins/default.js/wp-content/plugins/simply-gallery-block/blocks/skins/overlay.js/wp-content/plugins/simply-gallery-block/blocks/skins/slide.js/wp-content/plugins/simply-gallery-block/freemius/start.php
Script Paths
/wp-content/plugins/simply-gallery-block/assets/js/frontend.js/wp-content/plugins/simply-gallery-block/assets/js/lightbox.js
Version Parameters
simply-gallery-block/assets/css/frontend.css?ver=simply-gallery-block/assets/css/lightbox.css?ver=simply-gallery-block/assets/js/frontend.js?ver=simply-gallery-block/assets/js/lightbox.js?ver=simply-gallery-block/blocks/skins/default.js?ver=simply-gallery-block/blocks/skins/overlay.js?ver=simply-gallery-block/blocks/skins/slide.js?ver=

HTML / DOM Fingerprints

CSS Classes
pgc-simply-gallery-blockpgc-sgb-gallery-wrapperpgc-sgb-image-wrapperpgc-sgb-gallery-itempgc-sgb-lightboxpgc-sgb-lightbox-contentpgc-sgb-lightbox-closepgc-sgb-lightbox-prev+4 more
HTML Comments
<!-- SimpLy Gallery Block --><!-- SimpLy Gallery Block & Lightbox -->
Data Attributes
data-pgc-sgb-gallery-iddata-pgc-sgb-item-iddata-pgc-sgb-lightbox-contentdata-pgc-sgb-lightbox-closedata-pgc-sgb-lightbox-prevdata-pgc-sgb-lightbox-next
JS Globals
pgc_sgb_frontend_datapgc_sgb_lightbox_settingspgc_sgb_skins_listpgc_sgb_skins_presets
REST Endpoints
/wp-json/pgc-simply-gallery-block/v1/settings
FAQ

Frequently Asked Questions about SimpLy Gallery