Description
WordPress Plugin Photo Gallery-Image Gallery by Ape is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently deactivate any plugins on the blog. WordPress Plugin Photo Gallery-Image Gallery by Ape version 2.0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.7 or latest
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6606)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.3)
WordPress Plugin WP Symposium Arbitrary File Upload (14.11)
Dot CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-17422)
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2011-1134)