Input validation vulnerability in Video Gallery – YouTube Playlist, Channel Gallery by YotuWP 1.3.13

The YouTube Playlist and Channel Gallery plugin for WordPress, called YotuWP, has a security vulnerability that allows hackers to access and run any PHP code on the server. This can be done through the “display” function and affects all versions up to 1.3.13. Attackers with contributor access or higher can take advantage of this vulnerability to bypass security measures, access private information, or perform code execution. This can happen even if the uploaded files seem harmless, such as images.

Detected in:

Video Gallery – YouTube Playlist, Channel Gallery by YotuWP open vulnerable versions: >= * <= 1.3.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.