CVE-2014-5186

All Video Gallery 1.2 - Authenticated SQL Injection via id Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit action in the allvideogallery_videos page to wp-admin/admin.php.

References (1)

Core 1

Scores

EPSS 0.0158
EPSS Percentile 73.0%

Details

CWE
CWE-89
Status published
Products (1)
all_video_gallery_plugin_project/all-video-gallery 1.2
Published Aug 06, 2014
Tracked Since Feb 18, 2026