Gallery Objects <= 0.4 - SQL Injection
criticalSQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/admin-ajax.php.
- CVSS:
- 9.8
- Affected:
- up to 0.4
- Fix:
- No patched version reported
- Disclosed:
- Sep 19, 2014