WordPress Unite Gallery Lite plug-in SQL injection and Cross-Site Request Forgery Vulnerability
WordPress Unite Gallery Lite plug-in SQL injection and Cross-Site Request Forgery Vulnerability
Release date:
Updated on:
Affected Systems:
WordPress Unite Gallery Lite
Description:
Bugtraq id: 76043
Unite Gallery is the WordPress graphics and video library plug-in.
Unite Gallery Lite 1.4.6 and other versions have multiple cross-site Request Forgery vulnerabilities and multiple SQL Injection Vulnerabilities. Attackers can exploit these vulnerabilities to manipulate applications, access or modify data.
<* Source: Nitin Venkatesh
*>
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wordpress.org/plugins/unite-gallery-lite/
This article permanently updates the link address: