Access violation vulnerability in Portfolio Gallery – Responsive Image Gallery 1.4.5

The Portfolio Gallery – Responsive Image Gallery plugin for WordPress has a security issue that can allow unauthenticated attackers to modify the data and delete galleries without permission. This issue affects versions of the plugin up to and including 1.4.5 and is due to the TotalSoftPortfolio_Del_Callback() function being called via an AJAX action without any capability checks. Furthermore, there are other AJAX actions that can also be used to clone galleries and modify limited details for them.

Detected in:

Portfolio Gallery – Responsive Image Gallery open vulnerable versions: >= * <= 1.4.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.