plugin

Wp Upg Vulnerabilities

3 known security issues reported for the Wp Upg WordPress plugin. Most recent disclosed Jan 16, 2023.

1 critical

Running Wp Upg on your site? Check whether your installed version is affected.

Scan your site free

User Post Gallery &#8211; UPG [wp-upg] <= 2.19 (unfixed + closed)

unknown

[en] The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.

Affected:
up to 2.19
Fix:
No patched version reported
Disclosed:
Jan 16, 2023

CVE-2022-4060 on NVD →

User Post Gallery &#8211; UPG [wp-upg] <= 2.19 (unfixed + closed)

unknown
Affected:
up to 2.19
Fix:
No patched version reported
Disclosed:
Jan 3, 2023

CVE-2023-0039 on NVD →

User Post Gallery - UPG <= 2.19 - Missing Authorization to Remote Command Execution

critical

The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which leads to remote command execution due to the use of a nopriv AJAX action and user supplied function calls and parameters in versions up to, and including 2.19. This makes it possible for unauthenticated attackers to call arbitr...

CVSS:
9.8
Affected:
2.19 – 2.19
Fix:
No patched version reported
Disclosed:
Dec 26, 2022

CVE-2022-4060 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database