{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/the-gallery--4.7.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-2497"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Gallery (\u003c= 4.7.9)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","wordpress","sqli"],"_cs_type":"advisory","_cs_vendors":["BestWebSoft"],"content_html":"\u003cp\u003eThe Gallery by BestWebSoft plugin for WordPress, in all versions up to and including 4.7.9, contains a high-severity SQL injection vulnerability identified as CVE-2026-2497. The issue resides within the \u003ccode\u003egllr_save_postdata()\u003c/code\u003e function, which fails to adequately sanitize or escape user-supplied array keys from the \u003ccode\u003e$_POST\u003c/code\u003e parameter \u003ccode\u003e_gallery_order_{post_id}\u003c/code\u003e before processing them in SQL queries.\u003c/p\u003e\n\u003cp\u003eBecause the application fails to utilize prepared statements, an authenticated attacker with Editor-level permissions or higher can inject arbitrary SQL commands. Successful exploitation allows for unauthorized database queries, potentially leading to the extraction of sensitive information stored within the WordPress database. This vulnerability highlights the risks associated with improper handling of user-controllable input in plugin metadata save routines.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eAuthenticated attackers holding Editor-level privileges can leverage this vulnerability to gain unauthorized access to site data. This could result in the exfiltration of sensitive configuration details, user account information, or other confidential content stored within the database. Given the nature of WordPress plugins, successful exploitation poses a significant risk to site confidentiality and data integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT operations teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate The Gallery by BestWebSoft plugin to the latest version immediately to remediate CVE-2026-2497.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts to ensure that only trusted users are granted Editor-level or higher permissions, as this vulnerability requires elevated access.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests targeting gallery-related endpoints that include unexpected SQL syntax (e.g., SELECT, UNION, or comments) within the \u003ccode\u003e_gallery_order_\u003c/code\u003e parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T08:24:59Z","date_published":"2026-08-16T08:24:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-2497-sql-injection/","summary":"The Gallery by BestWebSoft plugin for WordPress up to version 4.7.9 contains an SQL injection vulnerability via the '_gallery_order_{post_id}' parameter allowing authenticated attackers with Editor-level access to extract database information.","title":"SQL Injection in The Gallery by BestWebSoft WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-2497-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - The Gallery (\u003c= 4.7.9)","version":"https://jsonfeed.org/version/1.1"}