Plugin Vulnerability Hub
Plugin 5 known issues Latest disclosed Mar 20, 2026

Photo Engine (Media Organizer & Lightroom) Vulnerabilities

Review known vulnerability records for the WordPress plugin Photo Engine (Media Organizer & Lightroom) (`wplr-sync`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-32524, CVE-2025-54672 and CVE-2024-43332, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
5
High or Critical
1
Patch Coverage
100%
Last Updated
Mar 27, 2026
Priority CVE Quick Links

Fast paths into Photo Engine (Media Organizer & Lightroom) CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
5
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Photo Engine (Media Organizer & Lightroom) so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
5 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 1 high severity finding.
Recent CVEs
CVE-2026-32524, CVE-2025-54672 and CVE-2024-43332
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Photo Engine (Media Organizer & Lightroom)

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-32524
CVE-2026-32524: Photo Engine (Media Organizer & Lightroom) <= 6.4.9 - Authenticated (Author+) Arbitrary File Upload

The Photo Engine (Media Organizer & Lightroom) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 6.4.9. This makes it possible for authenticated attackers, with Author-level access and above, to...

Published
Mar 20, 2026
Patched Release
6.5.0
Affected Versions
Versions up to 6.4.9
Next Step
Update to 6.5.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-54672
CVE-2025-54672: Photo Engine <= 6.4.3 - Cross-Site Request Forgery

The Photo Engine (Media Organizer & Lightroom) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to...

Published
Jul 30, 2025
Patched Release
6.4.4
Affected Versions
Versions up to 6.4.3
Next Step
Update to 6.4.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-43332
CVE-2024-43332: Photo Engine <= 6.4.0 - Missing Authorization

The Photo Engine (Media Organizer & Lightroom) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the rest_api_init() function in all versions up to, and including, 6.4.0. This makes it possible for authenticated attackers, with Subscri...

Published
Aug 16, 2024
Patched Release
6.4.1
Affected Versions
Versions up to 6.4.0
Next Step
Update to 6.4.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-39660
CVE-2024-39660: Photo Engine <= 6.3.1 - Authenticated (Author+) Stored Cross-Site Scripting

The Photo Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject...

Published
Aug 01, 2024
Patched Release
6.3.2
Affected Versions
Versions up to 6.3.1
Next Step
Update to 6.3.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-38513
CVE-2023-38513: Photo Engine <= 6.2.5 - Authenticated (Author+) Insecure Direct Object Reference in ajax_generate_auth_token

The Photo Engine plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.2.5. This is due to missing validation on a user controlled key within the ajax_generate_auth_token function. This makes it possible for unauthenticated att...

Published
Jul 20, 2023
Patched Release
6.2.6
Affected Versions
Versions up to 6.2.5
Next Step
Update to 6.2.6 or newer if supported.