Extension WordPress
Vulnérabilités WP Easy Gallery – WordPress Gallery Plugin
Cette page rassemble les failles publiées pour WP Easy Gallery – WordPress Gallery Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Easy Gallery – WordPress Gallery Plugin
10 fiches
WP Easy Gallery <= 4.8.5 – Authenticated (Contributor+) SQL Injection via key Parameter
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter…
*-4.8.5
Non indiqué
30/09/2024
WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 – Authenticated (Subscriber+) SQL Injection
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied…
*-4.8.5
Non indiqué
23/09/2024
WP Easy Gallery – WordPress Gallery Plugin <= 4.8.5 – Missing Authorization to Authenticated (Subscriber+) Gallery Manipulation
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX like wpeg_settings and wpeg_add_gallery in all versions up to, and…
*-4.8.5
Non indiqué
23/09/2024
WP Easy Gallery <= 4.1.4 – Stored Cross-Site Scripting
The WP Easy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_style’ parameter in versions before 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject…
[*, 4.1.5)
4.1.5
26/01/2016
WP Easy Gallery <= 2.7 – SQL Injection
The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' parameter in the 'admin/overview.php' file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied parameter and lack…
*-2.7
2.7.1
01/08/2014
WP Easy Gallery <= 2.7 – Cross-Site Request Forgery
The WP Easy Gallery for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers…
*-2.7
2.7.1
01/08/2014
PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 – DOM Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[*, 4.1.1)
4.1.1
01/08/2014
WP Easy Gallery <= 1.7 – Cross-Site Scripting
The WP Easy Gallery plugin for WordPress is vulnerable to Cross-Site Scripting via the 'select_gallery' and 'galleryId' parameters in versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.7
1.8
01/08/2014
WP Easy Gallery <= 2.7 – SQL Injection
The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' parameters found in the ‘admin/add-images.php’ file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied…
*-2.7
2.7.1
01/08/2014
WP Easy Gallery <= 2.7 – SQL Injection
The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' parameters found in the ‘admin/edit-gallery.php’ file in versions up to, and including, 2.7 due to insufficient escaping on the user-supplied…
*-2.7
2.7.1
18/02/2013
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.