WordPress Gallery Transforation < 0.7 - SQL Injection
criticalVulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.
- CVSS:
- 9.8
- Affected:
- up to 0.7
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2017