CVE-2019-14313
Description
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SQL injection in 10Web Photo Gallery plugin for WordPress before 1.5.31 allows remote attackers to execute arbitrary SQL commands via filemanager/model.php.
Vulnerability
A SQL injection vulnerability exists in the 10Web Photo Gallery plugin for WordPress versions before 1.5.31. The flaw resides in the filemanager/model.php file, where unsanitized user input is passed to SQL queries, allowing an attacker to inject arbitrary SQL commands. The plugin is widely used for creating mobile-friendly image galleries. [1]
Exploitation
An attacker can exploit this vulnerability remotely without authentication by sending a crafted HTTP request to the vulnerable endpoint. The attack requires no special privileges or user interaction, as the vulnerable code path is reachable through the file manager functionality. The attacker simply needs to manipulate input parameters to inject SQL statements.
Impact
Successful exploitation allows a remote attacker to execute arbitrary SQL commands on the WordPress database. This can lead to unauthorized access to sensitive data, including user credentials, posts, and configuration information. The attacker could also modify or delete database content, potentially compromising the entire WordPress installation.
Mitigation
The vulnerability is fixed in version 1.5.31 of the Photo Gallery plugin. Users should update to this version or later immediately. The plugin's developer, 10Web, has released the fix. As of the publication date (2019-07-30), no workarounds are documented. The plugin is actively maintained, and the latest version (1.8.41 as of the reference) includes the fix. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- 10Web/Photo Gallery plugindescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- fortiguard.com/zeroday/FG-VD-19-101mitrex_refsource_MISC
- plugins.trac.wordpress.org/changeset/2128378mitrex_refsource_CONFIRM
- wordpress.org/plugins/photo-gallery/mitrex_refsource_CONFIRM
- wpvulndb.com/vulnerabilities/9480mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.