Description
WordPress Plugin Gallery-Flagallery Photo Portfolio is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Gallery-Flagallery Photo Portfolio version 4.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.25 or latest
References
https://research.g0blin.co.uk/cve-2014-8491/
https://wordpress.org/plugins/flash-album-gallery/changelog/
Related Vulnerabilities
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-0735)
WordPress Plugin Lazyest Gallery 'image' Parameter Cross-Site Scripting (1.0.28)
Envoy Proxy Always-Incorrect Control Flow Implementation Vulnerability (CVE-2022-21655)
Oracle JRE CVE-2012-1717 Vulnerability (CVE-2012-1717)
WordPress Plugin Ultimate Membership Pro SQL Injection (6.4)