ReFlex Gallery < 1.4.3 - Cross-Site Scripting
mediumThe reflex-gallery plugin before 1.4.3 for WordPress has XSS via Edit Content URL field.
- CVSS:
- 6.1
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Aug 6, 2021
plugin
14 known security issues reported for the Reflex Gallery WordPress plugin. Most recent disclosed Aug 6, 2021.
Running Reflex Gallery on your site? Check whether your installed version is affected.
Scan your site freeThe reflex-gallery plugin before 1.4.3 for WordPress has XSS via Edit Content URL field.
[en] The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
[en] Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.
This plugin is prone to a shell upload vulnerability. Update plugin.
Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.
This vulnerability allows an attacker to upload arbitrary PHP code and execute it. Upgrade the plugin.
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
WordPress Reflex Gallery plugin is prone to an arbitrary file upload vulnerability. It allows an attacker to upload arbitrary files to the affected computer. Update the plugin.
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
The ReFlex Gallery » WordPress Photo Gallery for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.php file in versions up to, and including, 3.1.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make...
The ReFlex Gallery » WordPress Photo Gallery for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.php file in versions up to, and including, 3.1.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make...
The ReFlex Gallery » WordPress Photo Gallery WordPress plugin was affected by a Shell Upload security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free