Description
WordPress Plugin SLIDER PHOTO GALLERY is prone to multiple vulnerabilities, including arbitrary file download and SQL injection vulnerabilities. Exploiting these issues could allow an attacker to gain access to sensitive information, which may aid in launching further attacks, or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin SLIDER PHOTO GALLERY version 1.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
https://www.exploit-db.com/exploits/41567/
https://www.exploit-db.com/exploits/41568/
https://packetstormsecurity.com/files/141535/WordPress-Apptha-Slider-Gallery-1.0-SQL-Injection.html
Related Vulnerabilities
WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.30)
WordPress Plugin Contact Form to DB by BestWebSoft Cross-Site Scripting (1.5.6)
WordPress Plugin Category Grid View Gallery Cross-Site Scripting (2.3.3)
WordPress Plugin Translate WordPress-Google Language Translator Cross-Site Scripting (6.0.9)
WordPress Plugin Mikiurl WordPress Eklentisi Cross-Site Request Forgery (2.0)