CVE-2014-5201: Gallery Objects Project Gallery Objects
High severity, CVSS 7.5. EPSS: 4.6% chance of exploitation in the next 30 days.
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/admin-ajax.php.
Affected products
- Gallery Objects Project Gallery Objects: version 0.4 only
Published 2014-08-12. Last modified 2026-06-17.