7.8
CVSSv3

CVE-2019-14467

Published: 18/11/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

infoway social photo gallery 1.0

Exploits

WordPress Social Gallery plugin version 10 suffers from a remote code execution vulnerability ...