Description
WordPress Plugin SLIDER PHOTO GALLERY is prone to multiple vulnerabilities, including arbitrary file download and SQL injection vulnerabilities. Exploiting these issues could allow an attacker to gain access to sensitive information, which may aid in launching further attacks, or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin SLIDER PHOTO GALLERY version 1.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
https://www.exploit-db.com/exploits/41567/
https://www.exploit-db.com/exploits/41568/
https://packetstormsecurity.com/files/141535/WordPress-Apptha-Slider-Gallery-1.0-SQL-Injection.html
Related Vulnerabilities
WordPress Plugin WP-Live Chat by 3CX Cross-Site Scripting (7.1.04)
WordPress Plugin Product Catalog Cross-Site Scripting (4.2.8)
WordPress Plugin TheCartPress eCommerce Shopping Cart Multiple Vulnerabilities (1.5.3.6)
WordPress Plugin Disqus Comment System Multiple Cross-Site Request Forgery Vulnerabilities (2.77)