MEDIUM · 6.5

CVE-2014-2558

The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields...

Vulnerability Description

The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.

CVSS Score

6.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SkypheFile-Gallery<= 1.7.9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-2558?

CVE-2014-2558 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields...

How severe is CVE-2014-2558?

CVE-2014-2558 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-2558?

Check the references section above for vendor advisories and patch information. Affected products include: Skyphe File-Gallery.