ZM Gallery <= 1.0 - Authenticated (Admin+) SQL Injection
highThe zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
- CVSS:
- 7.2
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2016
plugin
1 known security issue reported for the Zm Gallery WordPress plugin. Most recent disclosed Dec 16, 2016.
Running Zm Gallery on your site? Check whether your installed version is affected.
Scan your site freeThe zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free