ImagePress – Image Gallery
ImagePress – Image Gallery has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 3 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10. 2024 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.
Every one of the 3 issues recorded for ImagePress – Image Gallery has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Michelle Porter. ImagePress – Image Gallery is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-9776ImagePress - Image Gallery <= 1.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings
Read the full analysisVulnerability Records

ImagePress – Image Gallery
Author
Ciprian Popescu
ImagePress is a WordPress image gallery plugin for sites that want to collect and display community photos. Visitors can upload images, add a short description, and organize their work into galleries. Use it for member galleries, photography communities, portfolios, or any site where people should be able to share images from the front end. ImagePress includes: Front-end image uploading and editing Separate, sortable, and filterable galleries Author profiles and portfolios A responsive layout that works with your WordPress theme Explore more WordPress Plugins. Check out the ImagePress PRO edition for advanced image variants, detail shots, progress shots, and front-end account features. View a free demo or learn about ImagePress PRO.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C