Input validation vulnerability in Album and Image Gallery plus Lightbox 1.6.2

The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to a type of attack known as Cross-Site Request Forgery. This vulnerability exists in versions up to and including 1.6.2 and is caused by missing or incorrect security measures on two of its AJAX actions. This means that unauthenticated attackers could potentially exploit this security flaw by tricking a site administrator into clicking on a malicious link. If successful, the attacker could change attributes of images used by the plugin in slideshows.

Detected in:

Album and Image Gallery plus Lightbox fixed vulnerable versions: >= * <= 1.6.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.