Description
WordPress Plugin Gallery-Flagallery Photo Portfolio is prone to multiple SQL injection, directory traversal and arbitrary file overwrite vulnerabilities. A successful exploit may allow an attacker to overwrite arbitrary files on the affected computer, compromise the application, disclose or delete potentially sensitive information, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Gallery-Flagallery Photo Portfolio version 2.00 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 2.17 or latest
References
Related Vulnerabilities
MySQL CVE-2020-14828 Vulnerability (CVE-2020-14828)
Perl Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-1999-1386)
WordPress Improper Input Validation Vulnerability (CVE-2019-20041)
WordPress Plugin Video Embed & Thumbnail Generator Information Disclosure (1.1)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-37147)