Input validation vulnerability in Gallery 1.3

The Gallery plugin used in WordPress is at risk of being hacked through a process called PHP Object Injection. This can happen in any version up to and including 1.3 when untrusted information is used in the wd_gallery_$id section. It allows someone who is logged in and has Contributor-level access or higher to insert a PHP Object. There is no known way for this to happen on its own, but if another plugin or theme is installed on the website, it could potentially let the attacker delete important files, access private information, or run their own code.

Detected in:

Gallery fixed vulnerable versions: >= * <= 1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.