10Web Photo Gallery < 1.5.55 - SQL Injection
CVE-2021-24139
Verified
Description
WordPress plugin 10Web Photo Gallery versions before 1.5.55 contains a SQL injection caused by unvalidated input in the 'bwg_search_x' parameter in frontend/models/model.php, letting attackers execute arbitrary SQL commands, exploit requires attacker to control the 'bwg_search_x' parameter.
Severity
Critical
CVSS Score
9.8
Exploit Probability
6%
Affected Product
photo_gallery
Published Date
January 29, 2026
Template Author
riteshs4hu
CVE-2021-24139.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2021-24139
CWE ID:
cwe-89
Remediation Steps
Update to version 1.5.55 or later.