Exhibit to WP Gallery
Exhibit to WP Gallery has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Exhibit to WP Gallery has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.
All of these findings were reported by Bob Matyas. The current release is tested up to WordPress 2.6.3.
CVE-2024-12096Exhibit to WP Gallery <= 0.0.2 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
Exhibit to WP Gallery
Author
ulfben
Exhibit to WP Gallery can convert your ancient Exhibit 1.1b entries to normal WordPress attachments. It assumes a linux host. Captions and image order will be transferred. All files will be copied to your upload folder. (use Custom Upload Dir for better structure!) New thumbnails will be generated according to your WordPress settings Lastly, the plugin will add ‘<br /> [gallery]‘ to the end of each post it touches. The plugin can list all posts currently using Exhibit, making it easy to visit them and make sure all went OK. The conversion is slow and painfull; the script might timeout. Therefore it is built so you can do it in chunks. Tip: Start with a single post and a few rows to make sure everything works before running through the entire table. Check the screenshots out for more info! Copyright (C) 2008 Ulf Benjaminsson (ulf a t ulfben d o t com). This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C