plugin

Reflex Gallery Vulnerabilities

14 known security issues reported for the Reflex Gallery WordPress plugin. Most recent disclosed Aug 6, 2021.

2 critical 2 medium

Running Reflex Gallery on your site? Check whether your installed version is affected.

Scan your site free

ReFlex Gallery < 1.4.3 - Cross-Site Scripting

medium

The reflex-gallery plugin before 1.4.3 for WordPress has XSS via Edit Content URL field.

CVSS:
6.1
Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Aug 6, 2021

CVE-2013-7482 on NVD →

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 1.4.3

unknown

[en] The reflex-gallery plugin before 1.4.3 for WordPress has XSS.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Aug 22, 2019

CVE-2013-7482 on NVD →

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 3.1.4

unknown

[en] Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
May 28, 2015

CVE-2015-4133 on NVD →

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 1.4.3

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
May 15, 2015

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 3.0.1

unknown

This plugin is prone to a shell upload vulnerability. Update plugin.

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
May 15, 2015

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 3.1.5

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
May 14, 2015

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 3.1.4

unknown

This vulnerability allows an attacker to upload arbitrary PHP code and execute it. Upgrade the plugin.

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Apr 21, 2015

ReFlex Gallery » WordPress Photo Gallery < 3.1.4 - Arbitrary File Upload

critical

Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.

CVSS:
9.8
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 16, 2015

CVE-2015-4133 on NVD →

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 3.1.4

unknown

WordPress Reflex Gallery plugin is prone to an arbitrary file upload vulnerability. It allows an attacker to upload arbitrary files to the affected computer. Update the plugin.

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Mar 8, 2015

PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

CVSS:
6.1
Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
Aug 1, 2014

CVE-2013-6837 on NVD →

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 3.1.5

unknown

[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

Affected:
up to 3.1.5
Fixed in:
3.1.5
Disclosed:
Dec 19, 2013

CVE-2013-6837 on NVD →

ReFlex Gallery » WordPress Photo Gallery < 3.1.4 - Arbitrary File Upload

critical

The ReFlex Gallery » WordPress Photo Gallery for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.php file in versions up to, and including, 3.1.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make...

CVSS:
9.8
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Jan 3, 2013

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 3.1.4

unknown

The ReFlex Gallery » WordPress Photo Gallery for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the php.php file in versions up to, and including, 3.1.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make...

Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Jan 3, 2013

ReFlex Gallery &#187; WordPress Photo Gallery [reflex-gallery] < 3.0.1

unknown

The ReFlex Gallery &raquo; WordPress Photo Gallery WordPress plugin was affected by a Shell Upload security vulnerability.

Affected:
up to 3.0.1
Fixed in:
3.0.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database