Description
WordPress Plugin SLIDER PHOTO GALLERY is prone to multiple vulnerabilities, including arbitrary file download and SQL injection vulnerabilities. Exploiting these issues could allow an attacker to gain access to sensitive information, which may aid in launching further attacks, or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin SLIDER PHOTO GALLERY version 1.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
https://www.exploit-db.com/exploits/41567/
https://www.exploit-db.com/exploits/41568/
https://packetstormsecurity.com/files/141535/WordPress-Apptha-Slider-Gallery-1.0-SQL-Injection.html
Related Vulnerabilities
WordPress Plugin OnePress Social Locker Multiple Cross-Site Scripting Vulnerabilities (4.2.0)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2015-2305)
Atlassian Jira Incorrect Behavior Order: Validate Before Canonicalize Vulnerability (CVE-2022-26136)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Multiple Vulnerabilities (5.2.3)