Unrated severityNVD Advisory· Published Dec 17, 2015· Updated May 6, 2026
CVE-2015-7527
CVE-2015-7527
Description
lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Width of preview image" and possibly other input fields in the "Video Gallery Settings" page.
Affected products
1- cpe:2.3:a:cool_video_gallery_project:cool_video_gallery:1.9:*:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- packetstormsecurity.com/files/134626/WordPress-Cool-Video-Gallery-1.9-Command-Injection.htmlnvdExploit
- www.openwall.com/lists/oss-security/2015/12/02/9nvdExploit
- www.vapidlabs.com/advisory.phpnvdExploit
- wordpress.org/support/topic/command-injection-vulnerability-in-v19nvdExploit
- www.securityfocus.com/archive/1/537051/100/0/threadednvd
- wpvulndb.com/vulnerabilities/8348nvd
News mentions
0No linked articles in our index yet.