CVE-2019-14314

CRITICAL

Imagely NextGEN Gallery <3.2.11 - SQL Injection

Title source: llm

Description

A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

Exploits (1)

nomisec WORKING POC 8 stars
by imthoe · poc
https://github.com/imthoe/CVE-2019-14314

Scores

CVSS v3 9.8
EPSS 0.3241
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
imagely/nextgen_gallery < 3.2.10
Published Aug 27, 2019
Tracked Since Feb 18, 2026