CVE-2019-14314: SQL Injection
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgengallerydisplay/package.module.nextgengallerydisplay.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14314?
CVE-2019-14314 is a SQL injection vulnerability in the Imagely NextGEN Gallery plugin before version 3.2.11 for WordPress.
How severe is CVE-2019-14314?
CVE-2019-14314 has a severity rating of 9.8 (Critical).
How does CVE-2019-14314 affect the affected software?
CVE-2019-14314 allows a remote attacker to execute arbitrary SQL commands on the affected system.
What is the affected software for CVE-2019-14314?
The affected software for CVE-2019-14314 is the Imagely NextGEN Gallery plugin before version 3.2.11 for WordPress.
How can I fix CVE-2019-14314?
To fix CVE-2019-14314, update the Imagely NextGEN Gallery plugin to version 3.2.11 or higher.