CVE-2014-5460
Tribulant Tibulant Slideshow Gallery - Improper Input Validation
Title source: ruleDescription
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Claudio Viviani · pythonwebappsphp
https://www.exploit-db.com/exploits/34681
exploitdb
WORKING POC
by Jesus Ramirez Pichardo · textwebappsphp
https://www.exploit-db.com/exploits/34514
metasploit
WORKING POC
EXCELLENT
by Jesus Ramirez Pichardo · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_slideshowgallery_upload.rb
References (8)
Scores
EPSS
0.6473
EPSS Percentile
98.5%
Details
CWE
CWE-20
Status
published
Products (7)
tribulant/tibulant_slideshow_gallery
1.4
tribulant/tibulant_slideshow_gallery
1.4.1
tribulant/tibulant_slideshow_gallery
1.4.2
tribulant/tibulant_slideshow_gallery
1.4.3
tribulant/tibulant_slideshow_gallery
1.4.4
tribulant/tibulant_slideshow_gallery
1.4.5
tribulant/tibulant_slideshow_gallery
< 1.4.6
Published
Sep 11, 2014
Tracked Since
Feb 18, 2026