CVE-2014-8375

Gb-plugins GB Gallery Slideshow - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Claudio Viviani · textwebappsphp
https://www.exploit-db.com/exploits/39282

References (3)

Core 3

Scores

EPSS 0.0139
EPSS Percentile 80.5%

Details

CWE
CWE-89
Status published
Products (1)
gb-plugins/gb_gallery_slideshow 1.5
Published Oct 21, 2014
Tracked Since Feb 18, 2026