CVE-2014-2558: Skyphe File-Gallery

Medium severity, CVSS 6.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.

Affected products

  • Skyphe File-Gallery: up to and including 1.7.9; version 1.1 only; version 1.2 only; version 1.3 only; version 1.4 only; version 1.5 only; …

Published 2014-05-06. Last modified 2026-06-17.