CVE-2016-10889: SQL Injection
Published Aug 14, 2019
·Updated
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress<2.1.57
Event History
Aug 14, 2019
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
Description
Frequently Asked Questions
1
What is CVE-2016-10889?
CVE-2016-10889 is a vulnerability in the nextgen-gallery plugin for WordPress that allows SQL injection via a gallery name.
2
How severe is CVE-2016-10889?
CVE-2016-10889 has a severity rating of 9.8 (Critical).
3
What is the affected software version for CVE-2016-10889?
The affected software version for CVE-2016-10889 is up to and excluding 2.1.57 of the nextgen-gallery plugin for WordPress.
4
How can I fix CVE-2016-10889?
To fix CVE-2016-10889, you should update the nextgen-gallery plugin for WordPress to version 2.1.57 or later.
5
Where can I find more information about CVE-2016-10889?
You can find more information about CVE-2016-10889 on the official WordPress plugin page: https://wordpress.org/plugins/nextgen-gallery/#developers