Image Photo Gallery Final Tiles Grid

Information

Software Type Plugin
Software Slug final-tiles-grid-gallery-lite (view on wordpress.org)
Software Status Active
Software Author wpchill
Software Downloads 995,737
Software Active Installs 20,000
Software Record Last Updated July 21, 2026

12 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Image Photo Gallery Final Tiles Grid <= 3.6.11 - Missing Authorization Patched CVE-2026-27424 4.3 Que Thanh Tuan May 20, 2026
Image Photo Gallery Final Tiles Grid <= 3.6.10 - Missing Authorization Patched CVE-2026-25375 4.3 Nabil Irawan February 18, 2026
Image Photo Gallery Final Tiles Grid <= 3.6.11 - Authenticated (Author+) Insecure Direct Object Reference Patched CVE-2026-39510 4.3 Athiwat Tiprasaharn (Jitlada) February 11, 2026
Image Photo Gallery Final Tiles Grid <= 3.6.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Gallery Management Patched CVE-2025-15466 5.4 Mohammad Amin Hajian (mamadrce), Pouria Shahba (p0or1ya) January 19, 2026
Image Photo Gallery Final Tiles Grid <= 3.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting Patched CVE-2025-13693 6.4 Athiwat Tiprasaharn (Jitlada), Itthidej Aramsri (Boeing777), Powpy, Waris Damkham, Varakorn Chanthasri (iCreaM), Peerapat Samatathanyakorn December 20, 2025
Image Photo Gallery Final Tiles Grid <= 3.6.7 - Missing Authorization to Authenticated (Contributor+) Gallery Management Patched CVE-2025-14455 5.4 JongHwan Shin (zzzsleep) December 18, 2025
Image Photo Gallery Final Tiles Grid <= 3.6.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting Patched CVE-2024-6261 6.4 Webbernaut February 26, 2025
Image Photo Gallery Final Tiles Grid <= 2.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2024-3710 6.4 Dmitrii Ignatyev June 22, 2024
Freemius SDK <= 2.4.2 - Missing Authorization Checks Patched CVE-2022-4974 6.3 March 4, 2022
Image Photo Gallery Final Tiles Grid <= 3.5.2 - Contributor+ Stored Cross-Site Scripting Patched CVE-2022-0186 5.4 Harshit, Siddhant Chouhan January 18, 2022
Final Tiles Gallery <= 3.4.18 - Authenticated Stored Cross-Site Scripting Patched CVE-2020-14962 6.4 Ngo Van Thien May 28, 2020
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update Patched 8.8 February 25, 2019

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation