CVE-2026-73185: WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress NGG Smart Image Search Pluginto a version that resolves this vulnerability.Fixed in 4.0.0
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
The vulnerability is unauthenticated and has network attack vector, so an attacker does not need a WordPress account or user interaction to attempt exploitation.
Which installations are affected?
WordPress sites using NGG Smart Image Search versions earlier than 4.0.0 are affected. The provided data does not identify any configuration prerequisite or mitigation other than moving to version 4.0.0 or later.
What is the potential impact?
Successful exploitation can expose sensitive data through SQL injection and may affect resources beyond the vulnerable component, as reflected by the high confidentiality impact and changed scope. Availability impact is rated low, while integrity impact is rated none.