Input validation vulnerability in WP Easy Gallery – WordPress Gallery Plugin 4.8.5

The WP Easy Gallery plugin for WordPress has a security vulnerability that allows hackers to access sensitive information from the database. This occurs when the ‘key’ parameter is used in the plugin, and it affects all versions up to 4.8.5. This vulnerability is due to inadequate preparation and escaping of user-supplied input in the SQL query. As a result, attackers with Contributor-level access or higher can add their own malicious SQL queries to the existing ones and retrieve sensitive information.

Detected in:

WP Easy Gallery – WordPress Gallery Plugin open vulnerable versions: >= * <= 4.8.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.