cleantalk
Vulnerabilities and Security Researches

WP Easy Gallery – WordPress Gallery Plugin, ab594533baaa27f6a7256975f5732c6a017c0199

Published on
Aug 01, 2014
Research Description
WP Easy Gallery &#8211; WordPress Gallery Plugin [wp-easy-gallery] < 2.7.1 (closed) WP Easy Gallery <= 2.7 - Cross-Site Request Forgery The WP Easy Gallery for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.7.1.
Status
vulnerable