Description
WordPress Plugin Cool Video Gallery is prone to a command injection vulnerability because it fails to properly validate user-supplied input. An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application. WordPress Plugin Cool Video Gallery version 1.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0 or latest
References
http://www.vapidlabs.com/advisory.php?v=158
http://www.openwall.com/lists/oss-security/2015/12/02/9
http://seclists.org/oss-sec/2015/q4/420
https://packetstormsecurity.com/files/134626/WordPress-Cool-Video-Gallery-1.9-Command-Injection.html
Related Vulnerabilities
WordPress Plugin Async JavaScript Cross-Site Scripting (2.20.12.09)
WordPress Plugin Warranties and Returns for WooCommerce Security Bypass (5.2.1)
WordPress Plugin WordPress WP-Advanced-Search Cross-Site Request Forgery (3.3.8)
WordPress Plugin Mingle Forum SQL Injection and Security Bypass Vulnerabilities (1.0.26)