plugin

Wp Powerplaygallery Vulnerabilities

13 known security issues reported for the Wp Powerplaygallery WordPress plugin. Most recent disclosed Jul 27, 2023.

3 critical 1 medium

Running Wp Powerplaygallery on your site? Check whether your installed version is affected.

Scan your site free

Powerplay Gallery [wp-powerplaygallery] < 1.1

unknown

Update plugin. An unknown person discovered and reported this Arbitrary File Upload vulnerability in WordPress Power Play Gallery Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnera...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2023

Powerplay Gallery [wp-powerplaygallery] < 1.1

unknown

Update the plugin. MustLive discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Power Play Gallery Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2023

Powerplay Gallery [wp-powerplaygallery] <= 3.3 (closed)

unknown

[en] upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.

Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
May 23, 2017

CVE-2015-5682 on NVD →

Powerplay Gallery [wp-powerplaygallery] < 1.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2016

Powerplay Gallery [wp-powerplaygallery] < 1.1 (closed)

unknown

This plugin is prone to an arbitrary file upload vulnerability. Update plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2016

Powerplay Gallery [wp-powerplaygallery] <= 3.3 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.

Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
Aug 18, 2015

CVE-2015-5599 on NVD →

Powerplay Gallery [wp-powerplaygallery] <= 3.3 (closed)

unknown

[en] Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/.

Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
Aug 18, 2015

CVE-2015-5681 on NVD →

Powerplay Gallery <= 3.3 - Arbitrary File Upload

critical

Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/.

CVSS:
9.8
Affected:
up to 3.3
Fix:
No patched version reported
Disclosed:
Jul 1, 2015

CVE-2015-5681 on NVD →

Powerplay Gallery <= 3.3 - Arbitrary File Upload

critical

upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.

CVSS:
9.8
Affected:
up to 3.3
Fix:
No patched version reported
Disclosed:
Jul 1, 2015

CVE-2015-5682 on NVD →

Powerplay Gallery <= 3.3 - SQL Injection

critical

Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.

CVSS:
9.8
Affected:
up to 3.3
Fix:
No patched version reported
Disclosed:
Jun 27, 2015

CVE-2015-5599 on NVD →

Powerplay Gallery [wp-powerplaygallery] < 3.2

unknown

[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
Jul 19, 2013

CVE-2012-3414 on NVD →

SWFUpload <= 2.2.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS:
6.1
Affected:
up to 3.2
Fixed in:
3.2
Disclosed:
Nov 9, 2012

CVE-2012-3414 on NVD →

Powerplay Gallery [wp-powerplaygallery] <= 3.3 (unfixed + closed)

unknown

The wp-powerplaygallery WordPress plugin was affected by an Arbitrary File Upload security vulnerability.

Affected:
up to 3.3
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database