CVE-2016-10940: Zm-Gallery Project Zm-Gallery

High severity, CVSS 7.2. EPSS: 5.6% chance of exploitation in the next 30 days.

The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.

Affected products

Published 2019-09-13. Last modified 2026-06-17.