CVE-2017-14125

CRITICAL

Responsive Image Gallery <1.2.1 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.

References (2)

Core 2
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/Sep/55
VDB Entry, Vendor Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/8907

Scores

CVSS v3 9.8
EPSS 0.0319
EPSS Percentile 86.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
wpdevart/responsive_image_gallery_gallery_album < 1.2.0
Published Sep 25, 2017
Tracked Since Feb 18, 2026