Beta

Report

Photo Gallery by 10Web <= 1.6.2 is vulnerable to Unauthenticated SQL Injection (SQLi) vulnerability

Unauthenticated
Published
2022-04-10

The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

CVSS

Score:8.3

Severity:High

Version: 1.6.2

There is a patch available in v1.6.3 and we strongly recommend you update to this version as soon as possible.