First published: Thu Mar 18 2021(Updated: )
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
10web Photo Gallery | <1.5.55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24139 is a vulnerability in the Photo Gallery (10Web Photo Gallery) WordPress plugin versions before 1.5.55.
CVE-2021-24139 has a severity level of critical (9.8).
CVE-2021-24139 allows SQL injection via the frontend/models/model.php bwg_search_x parameter in the Photo Gallery plugin before version 1.5.55.
To fix CVE-2021-24139, update the Photo Gallery (10Web Photo Gallery) WordPress plugin to version 1.5.55 or later.
You can find more information about CVE-2021-24139 at https://wpscan.com/vulnerability/2e33088e-7b93-44af-aa6a-e5d924f86e28.