CVE-2014-5201

Gallery Objects 0.4 - SQL Injection via viewid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-5201. PoCs published by Claudio Viviani.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WordPress Gallery Objects plugin version 0.4. The PoC provides a URL-based payload to trigger a boolean-based blind SQL injection via the 'viewid' parameter.

Description

SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/admin-ajax.php.

Exploits (1)

exploitdb WORKING POC
by Claudio Viviani · textwebappsphp
https://www.exploit-db.com/exploits/34105

This exploit demonstrates a SQL injection vulnerability in WordPress Gallery Objects plugin version 0.4. The PoC provides a URL-based payload to trigger a boolean-based blind SQL injection via the 'viewid' parameter.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress Gallery Objects plugin 0.4
No auth needed
Prerequisites: WordPress installation with Gallery Objects plugin 0.4 · Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.0459
EPSS Percentile 90.4%

Details

CWE
CWE-89
Status published
Products (1)
gallery_objects_project/gallery_objects 0.4
Published Aug 12, 2014
Tracked Since Feb 18, 2026