CVE-2019-14467: Infoway Social Photo Gallery

High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.

The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.

Affected products

  • Infoway Social Photo Gallery: version 1.0 only

Published 2019-11-18. Last modified 2026-06-17.