ZeroHour

CVE-2017-14125

PoC
CVSS 3.0
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.

Vendors
wpdevart
Products
responsive image gallery gallery album
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.