Vulnerabilities
Vulnerable Software
Ays-Pro:  Security Vulnerabilities
The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVSS Score
8.8
EPSS Score
0.005
Published
2021-08-02
The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVSS Score
8.8
EPSS Score
0.005
Published
2021-08-02
The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard
CVSS Score
8.8
EPSS Score
0.005
Published
2021-08-02
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-08-22


Contact Us

Shodan ® - All rights reserved