Description
WordPress Plugin WORDPRESS VIDEO GALLERY is prone to an open email relay vulnerability that lets attackers send mass emails without authentication. An attacker could exploit this issue to send unsolicited spam email to an unrestricted number of email addresses. WordPress Plugin WORDPRESS VIDEO GALLERY version 2.8 is vulnerable; other versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
http://www.homelab.it/index.php/2015/05/22/wordpress-video-gallery-2-8-unprotected-mail-page/
https://www.exploit-db.com/exploits/37106/
http://packetstormsecurity.com/files/132015/WordPress-Video-Gallery-2.8-Unprotected-Mail-Page.html
Related Vulnerabilities
WordPress Plugin Display Posts Shortcode Unspecified Vulnerability (1.9)
Oracle Database Server CVE-2009-0972 Vulnerability (CVE-2009-0972)
WordPress Plugin Disqus Comment System Cross-Site Scripting (2.68)
WordPress Plugin Custom Post View Generator Cross-Site Scripting (0.4.6)
WordPress Plugin Advanced Contact form 7 DB Information Disclosure (1.1.0)