SQL Injection Vulnerability in Gallery Objects Plugin for WordPress
CVE-2014-5201

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
12 August 2014

What is CVE-2014-5201?

The Gallery Objects plugin version 0.4 for WordPress is subject to an SQL injection vulnerability that enables remote attackers to execute arbitrary SQL commands. This breach occurs through the manipulation of the 'viewid' parameter during the 'go_view_object' action, specifically targeting wp-admin/admin-ajax.php. This flaw poses significant risks to the security of affected WordPress sites, allowing unauthorized access to sensitive database information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.