Description
WordPress Plugin Gallery-Flagallery Photo Portfolio is prone to multiple SQL injection, directory traversal and arbitrary file overwrite vulnerabilities. A successful exploit may allow an attacker to overwrite arbitrary files on the affected computer, compromise the application, disclose or delete potentially sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Gallery-Flagallery Photo Portfolio version 2.00 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 2.17 or latest
References
Related Vulnerabilities
Lighttpd Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2022-41556)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1914)
WordPress Plugin lasTunes Cross-Site Scripting (3.6.1)
WordPress Plugin Migration, Backup, Staging-WPvivid SQL Injection (0.9.52)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-0971)