plugin

Ungallery Vulnerabilities

2 known security issues reported for the Ungallery WordPress plugin. Most recent disclosed Apr 18, 2024.

1 critical 1 medium

Running Ungallery on your site? Check whether your installed version is affected.

Scan your site free

UnGallery <= 2.2.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The UnGallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.4. This is due to missing or incorrect nonce validation on the ungallerysettings page. This makes it possible for unauthenticated attackers to modify plugin settings and inject malicious webscripts v...

CVSS:
6.1
Affected:
up to 2.2.4
Fix:
No patched version reported
Disclosed:
Apr 18, 2024

CVE-2024-3582 on NVD →

UnGallery < 2.1.6 - Command Injection

critical

The UnGallery plugin for WordPress is vulnerable to Command Injection in versions before 2.1.6 via the 'search' parameter. This makes it possible for unauthenticated attackers to execute arbitrary commands on the server.

CVSS:
9.8
Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Oct 23, 2012

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database