plugin

Unite Gallery Lite Vulnerabilities

14 known security issues reported for the Unite Gallery Lite WordPress plugin. Most recent disclosed Aug 18, 2024.

1 critical 3 high 2 medium

Running Unite Gallery Lite on your site? Check whether your installed version is affected.

Scan your site free

Unite Gallery Lite [unite-gallery-lite] <= 1.7.62 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Valiano Unite Gallery Lite.This issue affects Unite Gallery Lite: from n/a through 1.7.62.

Affected:
up to 1.7.62
Fix:
No patched version reported
Disclosed:
Aug 18, 2024

CVE-2024-43207 on NVD →

Unite Gallery Lite <= 1.7.62 - Authenticated (Contributor+) SQL Injection

critical

The Unite Gallery Lite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.62 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
9.9
Affected:
up to 1.7.62
Fix:
No patched version reported
Disclosed:
Aug 9, 2024

CVE-2024-43207 on NVD →

Unite Gallery Lite [unite-gallery-lite] < 1.7.60 (closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Valiano Unite Gallery Lite allows PHP Local File Inclusion.This issue affects Unite Gallery Lite: from n/a through 1.7.59.

Affected:
up to 1.7.60
Fixed in:
1.7.60
Disclosed:
May 17, 2024

CVE-2023-33310 on NVD →

Unite Gallery Lite [unite-gallery-lite] < 1.7.62 (closed)

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Valiano Unite Gallery Lite plugin <= 1.7.61 versions.

Affected:
up to 1.7.62
Fixed in:
1.7.62
Disclosed:
Aug 30, 2023

CVE-2023-34183 on NVD →

Unite Gallery Lite <= 1.7.61 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Unite Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in versions up to, and including, 1.7.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbit...

CVSS:
4.4
Affected:
up to 1.7.61
Fixed in:
1.7.62
Disclosed:
May 30, 2023

CVE-2023-34183 on NVD →

Unite Gallery Lite <= 1.7.59 - Authenticated(Administrator+) Local File Inclusion via 'view' parameter

medium

The Unite Gallery Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.59 via the 'view' parameter. This allows authenticated attackers with administrator-level privileges to include and execute arbitrary files on the server, allowing the execution of any PHP code in tho...

CVSS:
5
Affected:
up to 1.7.59
Fixed in:
1.7.60
Disclosed:
May 22, 2023

CVE-2023-33310 on NVD →

Unite Gallery Lite [unite-gallery-lite] < 1.5 (closed)

unknown

[en] The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Sep 26, 2019

CVE-2015-9445 on NVD →

Unite Gallery Lite [unite-gallery-lite] < 1.5 (closed)

unknown

[en] The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Sep 26, 2019

CVE-2015-9446 on NVD →

Unite Gallery Lite [unite-gallery-lite] < 1.5 (closed)

unknown

[en] The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Sep 26, 2019

CVE-2015-9447 on NVD →

Unite Gallery Lite [unite-gallery-lite] < 1.4.7 (closed)

unknown

Unite Gallery Lite is prone to multiple vulnerabilities, such as CSRF and SQL injection. Update the plugin.

Affected:
up to 1.4.7
Fixed in:
1.4.7
Disclosed:
Jul 27, 2015

Unite Gallery Lite <= 1.4.6 - Cross-Site Request Forgery & Authenticated SQL Injection

high

The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.

CVSS:
8.8
Affected:
up to 1.4.6
Fixed in:
1.5
Disclosed:
Jul 25, 2015

CVE-2015-9445 on NVD →

Unite Gallery Lite < 1.5 - SQL Injection

high

The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.

CVSS:
8.8
Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Jul 25, 2015

CVE-2015-9446 on NVD →

Unite Gallery Lite < 1.5 - Cross-Site Request Forgery and SQL Injection

high

The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.

CVSS:
7.2
Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Jul 25, 2015

CVE-2015-9447 on NVD →

Unite Gallery Lite [unite-gallery-lite] < 1.7.61 (closed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.7.61
Fixed in:
1.7.61

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database