QID 150507
Date Published: 2022-05-05
QID 150507: WordPress Photo Gallery by 10Web Plugin: Unauthenticated SQL Injection Vulnerability (CVE-2022-0169)
Photo Gallery plugin is a feature-rich, yet easy-to-use WordPress tool, which lets you add mobile-friendly image galleries and gallery groups to your website.
The plugin does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection.
Affected Versions:
WordPress Photo Gallery Plugin before 1.6.0.
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary SQL queries on the target system.
CVEs related to QID 150507
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress |
|