Record summary

CVE-2016-10940 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWordPress zm-gallery plugin 1.0 SQL InjectionCVSS 7.2

zm-gallery plugin 1.0 for WordPress is susceptible to SQL injection via the order parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Update to the latest version of the zm-gallery plugin or apply the patch provided by the vendor.

WeaknessesCWE-89
Authorscckuailong, daffainfo
Template tagscvecve2016wpscansqliwpwordpresswp-pluginauthenticatedzm-gallery_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:zm-gallery_project:zm-gallery:1.0:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3