Input validation vulnerability in Portfolio Gallery – Photo Gallery 2.1.0

The Portfolio Gallery plugin for WordPress had a vulnerability in versions up to and including 2.1.0 that allowed unauthenticated attackers to inject malicious web scripts into pages. This was possible because the plugin did not properly check user input for malicious content before displaying it, or escape the malicious content before displaying it. This means that a user can be tricked into clicking on a link that would execute the malicious code on the page.

Detected in:

Portfolio Gallery – Photo Gallery open vulnerable versions: >= * <= 2.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.