CVE-2015-2065

Apptha WordPress Video Gallery < 2.7 - SQL Injection via vid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-2065. PoCs published by Claudio Viviani, Claudio Viviani, bperry, including Metasploit module auxiliary/scanner/http/wp_contus_video_gallery_sqli.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WordPress Video Gallery 2.7 via the 'vid' parameter in the admin-ajax.php endpoint. The PoC provides a URL template for exploitation and includes vendor-patched code for remediation.

Description

SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to wp-admin/admin-ajax.php.

Exploits (2)

exploitdb WORKING POC
by Claudio Viviani · textwebappsphp
https://www.exploit-db.com/exploits/36058

This exploit demonstrates a SQL injection vulnerability in WordPress Video Gallery 2.7 via the 'vid' parameter in the admin-ajax.php endpoint. The PoC provides a URL template for exploitation and includes vendor-patched code for remediation.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress Video Gallery 2.7
No auth needed
Prerequisites: WordPress Video Gallery 2.7 installed · Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit SCANNER
by Claudio Viviani, bperry · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_contus_video_gallery_sqli.rb

This Metasploit module scans for an unauthenticated UNION-based SQL injection vulnerability in WordPress Contus Video Gallery version 2.7. It sends a crafted HTTP request to test for the vulnerability by injecting a SQL payload and checking for a specific pattern in the response.

Classification
Scanner 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress Contus Video Gallery 2.7
No auth needed
Prerequisites: Target must be running WordPress with Contus Video Gallery plugin version 2.7 or prior
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74882
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/118419
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/36058

Scores

EPSS 0.4107
EPSS Percentile 98.5%

Details

CWE
CWE-89
Status published
Products (1)
apptha/wordpress_video_gallery < 2.7
Published Feb 24, 2015
Tracked Since Feb 18, 2026