CVE-2019-14467: Infoway Social Photo Gallery
High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.
The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.
Affected products
- Infoway Social Photo Gallery: version 1.0 only
Published 2019-11-18. Last modified 2026-06-17.