Description
WordPress Plugin Portfolio Gallery-Image Gallery is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Portfolio Gallery-Image Gallery version 1.1.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.3 or latest
References
Related Vulnerabilities
Drupal Core 8.9.x Directory Traversal (8.9.0 - 8.9.16)
WordPress Plugin Easy Comment Uploads 'upload.php' Arbitrary File Upload (0.61)
WordPress Plugin Media Library Categories 'termid' Parameter SQL Injection (1.0.6)
WordPress Plugin jQuery Mega Menu Widget 'skin' Parameter Local File Include (1.0)