The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.Referenceshttps://wordpress.org/plugins/social-photo-gallery/#developershttp://packetstormsecurity.com/files/155357/WordPress-Social-Photo-Gallery-1.0-Remote-Code-Execution.htmlhttps://wpvulndb.com/vulnerabilities/9952https://seclists.org/fulldisclosure/2019/Nov/13