CVE-2021-24139: Photo Gallery by 10Web < 1.5.55 - Unauthenticated SQL Injection
Published Mar 18, 2021
·Updated
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwgsearchx parameter.
Affected Software
1 affected component
10web Photo Gallery Wordpress<1.5.55
Event History
Mar 18, 2021
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24139?
CVE-2021-24139 is a vulnerability in the Photo Gallery (10Web Photo Gallery) WordPress plugin versions before 1.5.55.
2
What is the severity of CVE-2021-24139?
CVE-2021-24139 has a severity level of critical (9.8).
3
How does CVE-2021-24139 affect the Photo Gallery plugin?
CVE-2021-24139 allows SQL injection via the frontend/models/model.php bwg_search_x parameter in the Photo Gallery plugin before version 1.5.55.
4
How can I fix CVE-2021-24139?
To fix CVE-2021-24139, update the Photo Gallery (10Web Photo Gallery) WordPress plugin to version 1.5.55 or later.
5
Where can I find more information about CVE-2021-24139?
You can find more information about CVE-2021-24139 at https://wpscan.com/vulnerability/2e33088e-7b93-44af-aa6a-e5d924f86e28.