cleantalk
Vulnerabilities and Security Researches

Social Photo Gallery, CVE-2019-14467

CVE, Research URL

CVE-2019-14467

Application

Social Photo Gallery

Published on
Nov 18, 2019
Research Description
The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.
Affected versions
Min -, max 1.0.
Status
vulnerable