Critical severity9.8NVD Advisory· Published Jan 21, 2020· Updated Jun 17, 2026No known patch
CVE-2016-11018
No known patch is available for this vulnerability.
The affected plugin has been removed from the WordPress.org directory (reason: Guideline Violation), and no patched version is being distributed through the official directory. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
CVE-2016-11018
Description
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.9.0
Patches
Vulnerability mechanics
References
3- 10degres.net/cve-2016-11018-image-gallery-sql-injection/nvdExploitThird Party Advisory
- plugins.trac.wordpress.org/browser/gallery-images/tags/1.8.9nvdRelease NotesThird Party Advisory
- plugins.trac.wordpress.org/browser/gallery-images/tags/1.9.0nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.