plugin

Image Gallery With Slideshow Vulnerabilities

5 known security issues reported for the Image Gallery With Slideshow WordPress plugin. Most recent disclosed Apr 1, 2017.

4 critical 1 medium

Running Image Gallery With Slideshow on your site? Check whether your installed version is affected.

Scan your site free

Image Gallery with Slideshow <= 1.5.2 - SQL Injection via gallery_name

critical

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.

CVSS:
9.8
Affected:
up to 1.5.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2017

CVE-2017-1002014 on NVD →

Image Gallery with Slideshow Plugin <= 1.5.2 - SQL Injection via gid

critical

The Image Gallery with Slideshow plugin for WordPress is vulnerable to generic SQL Injection via the ‘gid’ parameter in versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticat...

CVSS:
9.8
Affected:
up to 1.5.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2017

CVE-2017-1002012 on NVD →

Image Gallery with Slideshow Plugin <= 1.5.2 - Blind SQL Injection via imgid

critical

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.

CVSS:
9.8
Affected:
up to 1.5.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2017

CVE-2017-1002013 on NVD →

Image Gallery with Slideshow <= 1.5.2 - SQL Injection via selectMulGallery

critical

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.

CVSS:
9.8
Affected:
up to 1.5.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2017

CVE-2017-1002015 on NVD →

Image Gallery with Slideshow Plugin <= 1.5.2 - Stored Cross-Site Scripting

medium

Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.

CVSS:
5.4
Affected:
up to 1.5.2
Fix:
No patched version reported
Disclosed:
Apr 1, 2017

CVE-2017-1002011 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database