References https://wpscan.com/vulnerability/5925b263-6d6f-4a03-a98a-620150dff8f7 https://avd.aquasec.com/nvd/2021/cve-2021-24667/ https://www.cve.org/CVERecord?id=CVE-2021-24667 https://jvndb.jvn.jp/ja/contents/2021/JVNDB-2021-011501.html https://www.fortiguard.com/zeroday/FG-VD-21-060 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simply-gallery-block https://acunetix.com/vulnerabilities/web/wordpress-plugin-gallery-blocks-with-lightbox-image-gallery-html5-video-youtube-vimeo-video-gallery-and-lightbox-for-native-gallery-cross-site-scripting-2-2-0/ https://vulnerability.circl.lu/search?product=simply_gallery_blocks_with_lightbox&vendor=simplygallery https://app.opencve.io/cve/?product=simply_gallery_blocks_with_lightbox&vendor=simplygallery https://nvd.nist.gov/vuln/detail/CVE-2021-24667
Related VulnerabilitiesPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞Wordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)WordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2022-1281: Photo Gallery WordPress v1.6.3 - SQL InjectionPoCCVE-2026-12394: WordPress MemberGlut < 1.1.5 - Unauthenticated Privilege EscalationPoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCCVE-2019-1003030: Jenkins Pipeline Groovy Plugin <=2.63 - Insecure DeserializationPoCsimple-file-list-rce: WordPress Simple File List <=4.2.2 - Remote Code ExecutionPoCCVE-2026-13147: WordPress Kirki < 6.0.12 - Server-Side Request ForgeryPoCCVE-2026-14894: WordPress Super Forms <= 6.3.313 - Arbitrary File Upload