plugin

Contus Video Gallery Vulnerabilities

19 known security issues reported for the Contus Video Gallery WordPress plugin. Most recent disclosed Apr 14, 2015.

4 critical 2 medium

Running Contus Video Gallery on your site? Check whether your installed version is affected.

Scan your site free

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.9 (closed)

unknown

This WordPress Video Gallery plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Apr 14, 2015

WORDPRESS VIDEO GALLERY <= 2.8 - SQL Injection

critical

The WORDPRESS VIDEO GALLERY Plugin for WordPress is vulnerable to SQL Injection via the ‘vid' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append addition...

CVSS:
9.8
Affected:
up to 2.8
Fixed in:
2.8.1
Disclosed:
Apr 13, 2015

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.8.1 (closed)

unknown

The WORDPRESS VIDEO GALLERY Plugin for WordPress is vulnerable to SQL Injection via the ‘vid' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append addition...

Affected:
up to 2.8.1
Fixed in:
2.8.1
Disclosed:
Apr 13, 2015

WORDPRESS VIDEO GALLERY <= 3.0 - Improper Access Control

medium

The WORDPRESS VIDEO GALLERY plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'email' ajax action in versions up to, and including, 3.0. This makes it possible for unauthorized attackers to perform various malicious actions such as Denial of Service, Phishing, spam, etc...

CVSS:
6.5
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Apr 5, 2015

WORDPRESS VIDEO GALLERY [contus-video-gallery] <= 3.0 (unfixed + closed)

unknown

The WORDPRESS VIDEO GALLERY plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'email' ajax action in versions up to, and including, 3.0. This makes it possible for unauthorized attackers to perform various malicious actions such as Denial of Service, Phishing, spam, etc...

Affected:
up to 3.0
Fix:
No patched version reported
Disclosed:
Apr 5, 2015

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.9 (closed)

unknown

This plugin is prone to an unprotected mail page vulnerability. Update the plugin.

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Apr 5, 2015

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.9 (closed)

unknown

WordPress Video Gallery plugin is prone to cross-site request forgery vulnerabilities. These vulnerabilities allow an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session. Upgrade the plugin.

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Apr 2, 2015

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.8 (closed)

unknown

[en] SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to wp-admin/admin-ajax.php.

Affected:
up to 2.8
Fixed in:
2.8
Disclosed:
Feb 24, 2015

CVE-2015-2065 on NVD →

Wordpress Video Gallery <= 2.7 - SQL Injection

critical

SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to wp-admin/admin-ajax.php.

CVSS:
9.8
Affected:
up to 2.8
Fixed in:
2.8
Disclosed:
Feb 12, 2015

CVE-2015-2065 on NVD →

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.7 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) remote attackers to execute arbitrary SQL commands via the vid parameter in a myextract action to wp-admin/admin-ajax.php or (2) remote...

Affected:
up to 2.7
Fixed in:
2.7
Disclosed:
Nov 26, 2014

CVE-2014-9097 on NVD →

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.6 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the videoadssearchQuery parameter to (1) videoads/videoads.php, (2) vide...

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Nov 26, 2014

CVE-2014-9098 on NVD →

WORDPRESS VIDEO GALLERY < 2.6 - SQL Injection

critical

Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) remote attackers to execute arbitrary SQL commands via the vid parameter in a myextract action to wp-admin/admin-ajax.php or (2) remote authe...

CVSS:
9.8
Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Jul 24, 2014

CVE-2014-9097 on NVD →

WORDPRESS VIDEO GALLERY <= 2.5 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the videoadssearchQuery parameter to (1) videoads/videoads.php, (2) video/vid...

CVSS:
5.4
Affected:
up to 2.5
Fixed in:
2.6
Disclosed:
Jul 24, 2014

CVE-2014-9098 on NVD →

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.1 (closed)

unknown

[en] SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the playid parameter to index.php.

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Mar 5, 2014

CVE-2013-3478 on NVD →

WordPress Video Gallery < 2.1 - SQL Injection

critical

SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the playid parameter to index.php.

CVSS:
9.8
Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
May 14, 2013

CVE-2013-3478 on NVD →

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 1.4 (closed)

unknown

Contus Video Gallery plugin's "upload1.php" is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible. Up...

Affected:
up to 1.4
Fixed in:
1.4
Disclosed:
Jun 12, 2012

WORDPRESS VIDEO GALLERY [contus-video-gallery] < 2.8.1 (closed)

unknown

Note: The vendor patched the issue but did not change the version number. Using fixed in version 2.8.1 for detection reasons although in reality this version does not exist at the time of writing.

Affected:
up to 2.8.1
Fixed in:
2.8.1

WORDPRESS VIDEO GALLERY [contus-video-gallery] <= 2.8 (unfixed + closed)

unknown

Any user can send email from /contus-video-gallery/email.php to any recipients.

Affected:
up to 2.8
Fix:
No patched version reported

WORDPRESS VIDEO GALLERY [contus-video-gallery] <= 2.8 (unfixed + closed)

unknown

The contus-video-gallery WordPress plugin was affected by a Multiple Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 2.8
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database