First published: Mon Aug 02 2021(Updated: )
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Photo Gallery | <4.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24462.
The affected software is the Photo Gallery by Ays - Responsive Image Gallery WordPress plugin version up to exclusive 4.4.4.
CVE-2021-24462 has a severity rating of 8.8 (High).
The CWE ID for CVE-2021-24462 is CWE-89 (SQL Injection).
To fix CVE-2021-24462, update the Photo Gallery by Ays - Responsive Image Gallery WordPress plugin to version 4.4.4 or higher.