vendor:
WordPress Huge-IT Video Gallery Plugin
by:
DefenseCode ThunderScan SAST Advisory
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: WordPress Huge-IT Video Gallery Plugin
Affected Version From: 2.0.4 and below
Affected Version To: 2.0.4 and below
Patch Exists: YES
Related CWE: N/A
CPE: a:huge_it:wordpress_huge-it_video_gallery_plugin
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress CMS
2017
WordPress Huge-IT Video Gallery Plugin Security Vulnerability
During the security audit of Huge-IT Video Gallery plugin for WordPress CMS, security vulnerability was discovered using DefenseCode ThunderScan application source code security analysis platform. The easiest way to reproduce the vulnerability is to visit the provided URL while being logged in as administrator or another user that is authorized to access the plugin settings page. Users that do not have full administrative privileges could abuse the database access the vulnerability provides to either escalate their privileges or obtain and modify database contents they were not supposed to be able to.
Mitigation:
The vendor has released an update that fixes the vulnerability. Version 2.0.5