vendor:
WordPress WebDorado Gallery Plugin
by:
DefenseCode ThunderScan SAST Advisory
6,5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: WordPress WebDorado Gallery Plugin
Affected Version From: 1.3.29 and below
Affected Version To: 1.3.30 and above
Patch Exists: YES
Related CWE: N/A
CPE: a:webdorado:wordpress_webdorado_gallery_plugin
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2017
WordPress WebDorado Gallery Plugin – SQL Injection Vulnerability
During the security analysis, ThunderScan discovered SQL injection vulnerability in WebDorado Gallery WordPress plugin. The easiest way to reproduce the vulnerability is to visit the provided URL while being logged in as administrator or another user that is authorized to access the plugin settings page. Any user with such privileges can obtain the valid bwg_nonce value by previously visiting the settings page. Users that to do not have full administrative privileges could abuse the database access the vulnerability provides to either escalate their privileges or obtain and modify database contents they were not supposed to be able to.
Mitigation:
Update to the latest version of the plugin, which is 1.3.30 or higher.