Security Advisory

CVE-2014-2558

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-05-06 14:00:00
Last updated 2024-08-06 10:21:34
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.