Impact
This CVE reveals an unauthenticated SQL Injection flaw that allows attackers to embed arbitrary SQL statements into queries executed by the Gmedia Photo Gallery plugin. Because the input is not properly sanitized, an attacker can read, modify, or delete database contents, leading to unauthorized data exposure and loss of integrity.
Affected Systems
The vulnerability affects the WordPress Gmedia Photo Gallery plugin managed by Serhii Pasyuk. All releases up to and including version 1.25.1 are impacted. Sites running these versions are at risk.
Risk and Exploitability
The vulnerability scores a CVSS of 9.3, indicating a high severity risk. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw without any authentication, making it widely accessible. The impact can lead to data theft, alteration, or deletion, which may compromise the confidentiality, integrity, and availability of the affected site.
OpenCVE Enrichment