Description
The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.
References (4)
Core 4
Core References
Patch x_refsource_misc
http://wordpress.org/plugins/file-gallery/changelog/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/67120
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Apr/305
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/67183
Scores
EPSS
0.0175
EPSS Percentile
75.0%
Details
CWE
CWE-94
Status
published
Products (31)
skyphe/file-gallery
1.1
skyphe/file-gallery
1.2
skyphe/file-gallery
1.3
skyphe/file-gallery
1.4
skyphe/file-gallery
1.5 (6 CPE variants)
skyphe/file-gallery
1.5.1
skyphe/file-gallery
1.5.2
skyphe/file-gallery
1.5.3
skyphe/file-gallery
1.5.4
skyphe/file-gallery
1.5.5
... and 21 more
Published
May 06, 2014
Tracked Since
Feb 18, 2026