Description
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery version 1.3.33 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.34 or latest
References
Related Vulnerabilities
WordPress Plugin Starbox-the Author Box for Humans Cross-Site Scripting (3.0.8)
WordPress Plugin Web Stories Server-Side Request Forgery (1.24.0)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-0145)
WordPress Plugin Social Slider Widget Cross-Site Scripting (1.8.4)
WordPress Plugin PayPal WP Button Manager SQL Injection (0.1.1)