Tribulant Gallery Voting

Tribulant Gallery Voting has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Tribulant Gallery Voting has a vendor fix available, so running the current release closes it.

All of these findings were reported by Abdi Pranata. Tribulant Gallery Voting is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Tribulant Gallery Voting vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-26931

Tribulant Gallery Voting <= 1.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Tribulant Gallery Voting banner
Latestv1.5

Tribulant Gallery Voting

Tribulant Software

Author

Tribulant Software

4.2(12)
84/100
Last Updated
2025-05-01 (1y ago)
Active Installs
300+
Downloads
19,022
Requires WP
3.8+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2014-05-06 (13y ago)

Simply let users (whether logged in or guest users, your choice) vote/like photos/images on your WordPress galleries. Users can also retract their votes, if the Unvoting feature is enabled by the admin. Installing and activating this plugin will place a vote/like link and a vote count below each photo of all WordPress image/photo galleries using the [gallery] shortcode. Online Demo You can try out the online demonstration to see how the plugin works. To log in, go to the demo dashboard and log in with demo / demo. Support & Help For support, you can access our support forums to see if your issue was previously resolved there. Otherwise, you can contact us on our support website or on the WordPress.org support forum. View the online documentation for installation and usage information.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C