Description
WordPress Plugin DZS Video Gallery is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin DZS Video Gallery version 3.1.3 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that input is properly verified or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Easy Accordion-Best Accordion FAQ Cross-Site Scripting (2.0.21)
WordPress Plugin Bulk Page Creator Cross-Site Scripting (1.0.9)
WordPress Plugin FileBird-WordPress Media Library Folders & File Manager Cross-Site Scripting (2.4)
WordPress Plugin WP-Forum Multiple SQL Injection Vulnerabilities (2.3)
WordPress Plugin mb.YTPlayer for background videos Unspecified Vulnerability (1.7.2)