Executive brief
PICA Photo Gallery is a WordPress plugin used to manage and display image galleries on websites. A security flaw in this plugin allows unauthorized individuals to access the website's underlying database without needing a password. This could lead to the theft of sensitive information, including user credentials and private site data, potentially compromising the entire website.
Technical details
A SQL injection vulnerability exists in the PICA Photo Gallery plugin version 1.0 for WordPress. The flaw is located in the handling of the 'aid' parameter, which fails to properly sanitize user input before using it in a database query. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request containing SQL payloads. Successful exploitation allows the attacker to bypass authentication, extract sensitive data from the database (such as the wp_users table), and potentially modify database contents. A public exploit (EDB-41569) has been available since 2017.
Affected products
- Apptha PICA Photo Gallery 1.0
Timeline
- 2017-03-09: disclosed: Initial exploit published on Exploit-DB
- 2026-06-09: advisory: NVD/VulnCheck advisory published