216.73.217.24

CVE-2021-24139

· Published 18/03/2021 16:15 · Modified 23/07/2026 17:16 · Author: The MITRE Corporation

Labels: CVE-2021-24139

Essential information

Published
18/03/2021 16:15
Modified
23/07/2026 17:16
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

NVD status

NVD
View on NVD