Description
Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
Published: 2026-10-06
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Data Exfiltration
Action: Immediate Patch
AI Analysis

Impact

This CVE reveals an unauthenticated SQL Injection flaw that allows attackers to embed arbitrary SQL statements into queries executed by the Gmedia Photo Gallery plugin. Because the input is not properly sanitized, an attacker can read, modify, or delete database contents, leading to unauthorized data exposure and loss of integrity.

Affected Systems

The vulnerability affects the WordPress Gmedia Photo Gallery plugin managed by Serhii Pasyuk. All releases up to and including version 1.25.1 are impacted. Sites running these versions are at risk.

Risk and Exploitability

The vulnerability scores a CVSS of 9.3, indicating a high severity risk. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw without any authentication, making it widely accessible. The impact can lead to data theft, alteration, or deletion, which may compromise the confidentiality, integrity, and availability of the affected site.

Generated by OpenCVE AI on October 6, 2026 at 11:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest version of the Gmedia Photo Gallery plugin (any release newer than 1.25.1).
  • If an update is not feasible immediately, disable or remove the plugin from the WordPress installation to block the attack surface.
  • Apply application-level input validation, ensuring that all incoming parameters used in database queries are bound using prepared statements or parameterized queries in accordance with CWE-89 best practices.

Generated by OpenCVE AI on October 6, 2026 at 11:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions.
Title WordPress Gmedia Photo Gallery plugin <= 1.25.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:34.417Z

Reserved: 2026-04-07T10:59:15.736Z

Link: CVE-2026-39785

cve-icon Vulnrichment

Updated: 2026-10-06T10:29:30.886Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:51.100

Modified: 2026-10-06T11:17:25.587

Link: CVE-2026-39785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:15:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')