WordPress plugin 10Web Photo Gallery versions before 1.5.55 contains a SQL injection caused by unvalidated input in the 'bwg_search_x' parameter in frontend/models/model.php, letting attackers execute arbitrary SQL commands, exploit requires attacker to control the 'bwg_search_x' parameter.
id: CVE-2021-24139
info:
name: 10Web Photo Gallery < 1.5.55 - SQL Injection
author: riteshs4hu
...