Description
WordPress Plugin Gallery-Flagallery Photo Portfolio is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Gallery-Flagallery Photo Portfolio version 4.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.25 or latest
References
https://research.g0blin.co.uk/cve-2014-8491/
https://wordpress.org/plugins/flash-album-gallery/changelog/
Related Vulnerabilities
WordPress Plugin WP Mass Mail Open Email Relay (2.45)
WordPress Plugin WP Cost Estimation & Payment Forms Builder Multiple Vulnerabilities (9.642)
WordPress Plugin Pinpoint Booking System (+WooCommerce) SQL Injection (2.0)
WordPress Plugin Email Templates HTML Injection (1.3)
WordPress Plugin Kindeditor For WordPress Cross-Site Scripting (1.3.3)