Unauthenticated SQL Injection Vulnerability in NGG Smart Image Search by WordPress
CVE-2026-73185
9.3CRITICAL
What is CVE-2026-73185?
The NGG Smart Image Search plugin for WordPress is prone to an unauthenticated SQL injection vulnerability that affects versions prior to 4.0.0. This vulnerability allows attackers to exploit the plugin and gain unauthorized access to the database, potentially exposing sensitive information and enabling further attacks on the website. Website owners using the affected versions are encouraged to update to the latest version to mitigate this security risk.
Affected Version(s)
NGG Smart Image Search < 4.0.0
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jarno Vos (jrn5151) | Patchstack Bug Bounty Program