WP jQuery Pager <= 1.4.0 - Authenticated (Contributor+) SQL Injection via Shortcode
mediumThe WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter handled by the WPJqueryPaged::get_gallery_page_imgs() function in all versions up to, and including, 1.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
- CVSS:
- 6.5
- Affected:
- up to 1.4.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 14, 2025