Powerplay Gallery [wp-powerplaygallery] < 1.1
unknown
Update plugin.
An unknown person discovered and reported this Arbitrary File Upload vulnerability in WordPress Power Play Gallery Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnera...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 27, 2023
Powerplay Gallery [wp-powerplaygallery] < 1.1
unknown
Update the plugin.
MustLive discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Power Play Gallery Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit...
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 27, 2023
Powerplay Gallery [wp-powerplaygallery] <= 3.3 (closed)
unknown
[en] upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- May 23, 2017
CVE-2015-5682 on NVD →
Powerplay Gallery [wp-powerplaygallery] < 1.1 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 27, 2016
Powerplay Gallery [wp-powerplaygallery] < 1.1 (closed)
unknown
This plugin is prone to an arbitrary file upload vulnerability.
Update plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 27, 2016
Powerplay Gallery [wp-powerplaygallery] <= 3.3 (closed)
unknown
[en] Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Aug 18, 2015
CVE-2015-5599 on NVD →
Powerplay Gallery [wp-powerplaygallery] <= 3.3 (closed)
unknown
[en] Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/.
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Aug 18, 2015
CVE-2015-5681 on NVD →
Powerplay Gallery <= 3.3 - Arbitrary File Upload
critical
Unrestricted file upload vulnerability in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in *_uploadfolder/big/.
- CVSS:
- 9.8
- Affected:
- up to 3.3
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2015
CVE-2015-5681 on NVD →
Powerplay Gallery <= 3.3 - Arbitrary File Upload
critical
upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.
- CVSS:
- 9.8
- Affected:
- up to 3.3
- Fix:
- No patched version reported
- Disclosed:
- Jul 1, 2015
CVE-2015-5682 on NVD →
Powerplay Gallery <= 3.3 - SQL Injection
critical
Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.
- CVSS:
- 9.8
- Affected:
- up to 3.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 27, 2015
CVE-2015-5599 on NVD →
Powerplay Gallery [wp-powerplaygallery] < 3.2
unknown
[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- Jul 19, 2013
CVE-2012-3414 on NVD →
SWFUpload <= 2.2.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- CVSS:
- 6.1
- Affected:
- up to 3.2
- Fixed in:
- 3.2
- Disclosed:
- Nov 9, 2012
CVE-2012-3414 on NVD →
Powerplay Gallery [wp-powerplaygallery] <= 3.3 (unfixed + closed)
unknown
The wp-powerplaygallery WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 3.3
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database