Input validation vulnerability in WP Easy Gallery – WordPress Gallery Plugin 2.7

The WP Easy Gallery plugin for WordPress is vulnerable to a type of security vulnerability called generic SQL Injection, which affects versions of the plugin up to 2.7. This security vulnerability occurs when malicious attackers are able to append additional SQL queries into existing queries in the ‘admin/add-images.php’ file. This could potentially allow attackers to extract sensitive information from the database. This vulnerability occurs because of insufficient escaping on user-supplied parameters and insufficient preparation of existing SQL queries.

Detected in:

WP Easy Gallery – WordPress Gallery Plugin open vulnerable versions: >= * <= 2.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.