### [CVE-2021-24462](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24462) ![](https://img.shields.io/static/v1?label=Product&message=Photo%20Gallery%20by%20Ays%20%E2%80%93%20Responsive%20Image%20Gallery&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=4.4.4%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-89%20SQL%20Injection&color=brightgreen) ### Description The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard ### POC #### Reference - https://wpscan.com/vulnerability/e24dac6d-de48-42c1-bdde-4a45fb331376 #### Github - https://github.com/20142995/nuclei-templates