Photo Gallery WordPress plugin v1.6.3 contains a SQL injection caused by improper escaping of $_POST['filter_tag'] parameter in SQL queries, letting attackers execute arbitrary SQL commands, exploit requires sending crafted POST requests.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view