Description
WordPress Plugin SLIDER PHOTO GALLERY is prone to multiple vulnerabilities, including arbitrary file download and SQL injection vulnerabilities. Exploiting these issues could allow an attacker to gain access to sensitive information, which may aid in launching further attacks, or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin SLIDER PHOTO GALLERY version 1.0 is vulnerable.
Remediation
Disable the plugin until a fix is available
References
https://www.exploit-db.com/exploits/41567/
https://www.exploit-db.com/exploits/41568/
https://packetstormsecurity.com/files/141535/WordPress-Apptha-Slider-Gallery-1.0-SQL-Injection.html
Related Vulnerabilities
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4554)
WordPress Plugin FileBird-WordPress Media Library Folders & File Manager SQL Injection (4.7.3)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.13)
WordPress Plugin Gmedia Photo Gallery Arbitrary File Upload (1.2.1)