Tribulant Gallery Voting
Tribulant Gallery Voting has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Tribulant Gallery Voting has a vendor fix available, so running the current release closes it.
All of these findings were reported by Abdi Pranata. Tribulant Gallery Voting is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-26931Tribulant Gallery Voting <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Tribulant Gallery Voting
Author
Tribulant Software
Simply let users (whether logged in or guest users, your choice) vote/like photos/images on your WordPress galleries. Users can also retract their votes, if the Unvoting feature is enabled by the admin. Installing and activating this plugin will place a vote/like link and a vote count below each photo of all WordPress image/photo galleries using the [gallery] shortcode. Online Demo You can try out the online demonstration to see how the plugin works. To log in, go to the demo dashboard and log in with demo / demo. Support & Help For support, you can access our support forums to see if your issue was previously resolved there. Otherwise, you can contact us on our support website or on the WordPress.org support forum. View the online documentation for installation and usage information.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C