Gallery from files [gallery-from-files] <= 1.6.0 (unfixed + closed)
unknown
[en] This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, t...
- Affected:
- up to 1.6.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 14, 2021
CVE-2021-24349 on NVD →
Gallery From Files <= 1.60 - Arbitrary File Upload
critical
The Gallery From Files plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.60 via improperly implemented allowed extension checks. This allows unauthenticated attackers to upload malicious files to the server which can be used to obtain remote code exectution.
- CVSS:
- 9.8
- Affected:
- up to 1.60
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2021
Gallery from files <= 1.60 - Reflected Cross-Site Scripting
medium
This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the at...
- CVSS:
- 6.1
- Affected:
- up to 1.60
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2021
CVE-2021-24349 on NVD →
Gallery from files [gallery-from-files] <= 1.60 (unfixed + closed)
unknown
Unauthenticated Remote Code Execution (RCE) vulnerability discovered by WPScanTeam in WordPress Gallery from files plugin (versions <= 1.60).
- Affected:
- up to 1.60
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2021
Gallery from files [gallery-from-files] <= 1.60 (unfixed + closed)
unknown
The Gallery From Files plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.60 via improperly implemented allowed extension checks. This allows unauthenticated attackers to upload malicious files to the server which can be used to obtain remote code exectution.
- Affected:
- up to 1.60
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2021
Gallery from files [gallery-from-files] <= 1.6.0 (unfixed + closed)
unknown
The upload feature of the plugin does not properly check for the allowed extensions, allowing them to be set in the request and attempting to remove the dangerous ones (such as .php and .js), but forgetting about .php4, .html etc. As a result, unauthenticated users could upload arbitrary .php4 files on the web server a...
- Affected:
- up to 1.6.0
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database