WordPress Video Gallery <= 2.8 - SQL Injection
The plugin does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection.
contus-video-galleryPoC 已收录
CVSS—