References https://wpscan.com/vulnerability/5925b263-6d6f-4a03-a98a-620150dff8f7 https://avd.aquasec.com/nvd/2021/cve-2021-24667/ https://www.cve.org/CVERecord?id=CVE-2021-24667 https://jvndb.jvn.jp/ja/contents/2021/JVNDB-2021-011501.html https://www.fortiguard.com/zeroday/FG-VD-21-060 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simply-gallery-block https://acunetix.com/vulnerabilities/web/wordpress-plugin-gallery-blocks-with-lightbox-image-gallery-html5-video-youtube-vimeo-video-gallery-and-lightbox-for-native-gallery-cross-site-scripting-2-2-0/ https://vulnerability.circl.lu/search?product=simply_gallery_blocks_with_lightbox&vendor=simplygallery https://app.opencve.io/cve/?product=simply_gallery_blocks_with_lightbox&vendor=simplygallery https://nvd.nist.gov/vuln/detail/CVE-2021-24667
Related VulnerabilitiesPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCCVE-2026-87902: WordPress Core - PHP Template Path TraversalPoCCVE-2026-80099: Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC SecretPoCCVE-2026-13153: Essential Blocks < 6.4.0 - Information DisclosurePoCCVE-2026-84434: WordPress Gravity Forms Plugin <=3.1.0.4 - Unauthenticated Arbitrary File UploadPoCwordpress-click2shell: WordPress Click2Shell Theme Preview Selector InjectionPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞Wordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)WordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2022-1281: Photo Gallery WordPress v1.6.3 - SQL Injection