/Vulnerability Library

10Web Photo Gallery < 1.5.55 - SQL Injection

CVE-2021-24139
Verified

Description

WordPress plugin 10Web Photo Gallery versions before 1.5.55 contains a SQL injection caused by unvalidated input in the 'bwg_search_x' parameter in frontend/models/model.php, letting attackers execute arbitrary SQL commands, exploit requires attacker to control the 'bwg_search_x' parameter.

Severity

Critical

CVSS Score

9.8

Exploit Probability

6%

Affected Product

photo_gallery

Published Date

January 29, 2026

Template Author

riteshs4hu

CVE-2021-24139.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2021-24139
CWE ID:
cwe-89

References

https://wpscan.com/vulnerability/2e33088e-7b93-44af-aa6a-e5d924f86e28https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/photo-gallery/photo-gallery-by-10web-1554-sql-injection-via-bwg-search-x-parameterhttps://nvd.nist.gov/vuln/detail/CVE-2021-24139

Remediation Steps

Update to version 1.5.55 or later.