Back

HIGH

Gallery by BestWebSoft < 4.7.0 - Author+ SQL Injection

Published Apr 17, 2023

Description

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Apr 17, 2023
Updated Mar 5, 2025
Reserved Feb 9, 2023
CISA Vulnrichment
Updated Mar 5, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WPScan
Published Apr 17, 2023
Updated Mar 5, 2025
Exploited since n/a
EUVD-2023-12782