Input validation vulnerability in Gmedia Photo Gallery 1.6.5

The Gmedia Photo Gallery plugin for WordPress is a software that is vulnerable to a type of cyber attack known as Local File Inclusion. This plugin is used in versions up to 1.6.4 and is exploitable if a setting called ALLOW_NO_EXT is set to true. With this vulnerability, unauthenticated attackers can include and execute any files on the server, allowing them to run malicious code. This could result in bypassing security measures, stealing sensitive data, or even taking over the system if allowed file types such as images can be uploaded and included.

Detected in:

Gmedia Photo Gallery fixed vulnerable versions: >= * < 1.6.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.