Input validation vulnerability in Tinymce Thumbnail Gallery 1.0.7

The Tinymce Thumbnail Gallery plugin for WordPress is affected by a security issue that can allow unauthenticated attackers to access certain files from a WordPress website. This affects versions of the plugin up to and including 1.0.7. A file called download-image.php found in the php folder contains a parameter called ‘href’ which is vulnerable to Local File Inclusion. This means that if an attacker is able to access this file, they could potentially gain access to files such as wp-config.php, which can contain sensitive information.

Detected in:

Tinymce Thumbnail Gallery fixed vulnerable versions: >= * <= 1.0.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.