Security vulnerability: myGallery plugin for WordPress

The other morning, Rebecca told me about some problems with the RadioZoom site. Essentially, it didn’t want to load at all. There was a consistent error with some PHP in the myGallery plugin that I have been using on the site. I don’t use it extensively, and it was mostly to showcase some photos of a soundseeing episode that I did while wandering through Stanley Park.

Mark Ghosh made a post yesterday that answered a lot of my questions about the problem I ran into.

MyGallery Plugin for WordPress If you are using the myGallery plugin for WordPress to display your pictures, please follow the link above and update your plugin to the latest version. A pretty serious remote code execution vulnerability in the plugin has been found and disclosed and there have been scattered reports of hack attempts. [weblogtoolscollection]

I thought it was fairly strange for a plugin to just stop working, and there was a hunch inside of me that was fearing a hacker trying to get into the site, not that there is a whole lot to really get into. This is why I do regular backups to the site, not to mention keeping an archive of all the episodes that are released.

Even though this “error” completely crippled the site, I was able to remove the plugin physically on the server and gain access again. It disallowed me from getting to my dashboard as well. Everything is updated and appears to be running smoothly. If you use it, I would seriously consider upgrading ASAP. I’m fairly sure that my problem was the result of a hacker, so it can happen.

Advertisement