QID 150519
Date Published: 2022-06-04
QID 150519: WordPress Photo Gallery Plugin: Unauthenticated SQL Injection Vulnerability (CVE-2022-1281)
Photo Gallery plugin is a feature-rich, yet easy-to-use WordPress tool, which lets you add mobile-friendly image galleries and gallery groups to your website.
The plugin does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.
Affected Versions:
WordPress Photo Gallery Plugin before 1.6.3.
QID Detection Logic:
This QID sends a HTTP POST request to "/wp-admin/admin-ajax.php" with SQL Injection payload and based on the response confirms if the target is vulnerable.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary SQL queries on the target system.
Solution
Customers are advised to install latest Photo Gallery version.
If upgrading is not possible, please refer to mitigation details mentioned on WordPress site.
If upgrading is not possible, please refer to mitigation details mentioned on WordPress site.
Vendor References
CVEs related to QID 150519
Software Advisories