WordPress Plugin Tinymce Thumbnail Gallery 'href' Parameter Information Disclosure (1.0.7)

Description
  • WordPress Plugin Tinymce Thumbnail Gallery is prone to an information disclosure vulnerability because it fails to properly sanitize user-supplied input. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Tinymce Thumbnail Gallery version 1.0.7 is vulnerable; prior versions may also be affected.
Remediation
  • Update to plugin version 1.1.0 or latest
References