Garden Gnome Package

Garden Gnome Package has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 7.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.

Every one of the 4 issues recorded for Garden Gnome Package has a vendor fix available, so running the current release closes all known holes.

4 independent researchers contributed these findings, one record each. Garden Gnome Package is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
7.0/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all Garden Gnome Package vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-12854

Garden Gnome Package <= 2.3.0 - Authenticated (Author+) Arbitrary File Upload

Read the full analysis

Vulnerability Records

4 records
Garden Gnome Package banner
Latestv2.5.3

Garden Gnome Package

Chief Gnome

Author

Chief Gnome

4.2(5)
84/100
Last Updated
2026-05-28 (4mo ago)
Active Installs
4,000+
Downloads
60,379
Requires WP
5.0+
Requires PHP
7.2+
Tested up to
WP 7.0.4
Created
2019-06-26 (7y ago)

This plugin provides an easy way to publish panoramas and object movies created with Garden Gnome Software’s Pano2VR and Object2VR. You can embed a package via a shortcode like [ggpkg id=12] or a block in the Gutenberg editor. In the plugin settings, you can restrict .ggpkg uploads to users with a specific WordPress capability. This check is enabled by default and uses upload_ggpkg unless you change it. Sample packages can be downloaded from our forum. Shortcode When you are using a shortcode to embed a package, you can provide additional parameters in the shortcode: width: the width of the player in the page height: the height of the player in the page start_preview: when set to &#8216;true’, the player will initially show as a preview image with a play button. start_node: if the package is a virtual tour, you can specify the start node. You can find the node ID of each node in the tooltip in the tour browser. start_view: for panoramas and virtual tours, sets the initial view of the first node. The format is &#8216;pan/tilt/fov/projection’. The projection parameter is optional. url: can be used instead of ID, to embed a package from a specific URL. Like [ggpkg url='....']. This field needs to be enabled in the settings. Remote URL security: when using url, you can enforce TLS certificate verification and optionally restrict allowed hostnames in the plugin settings. Example: [ggpkg id=12 width='100%' height='500px' start_preview='true'] If you are using the Gutenberg Editor and want to embed a package via a shortcode, use a Classic Block from the &#8216;Formatting’ section, and use the Add Media button to add a package from the media library. Gutenberg Block You can find the GGPKG Gutenberg Block in the Widgets section. In the GGPKG Block, you can pick a package from the media library. In the Inspector panel on the right, you can specify if the package should start with a preview image and a play button, and set the width and height of the player in the page. Elementor Widget You can find the Garden Gnome Package Widget in the General section. In the Widget settings, you can pick a package from the media library, define the height, and select if it should start with a preview image.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C