CVE-2017-1002028: Angrybyte Gallery-Transformation

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.

Affected products

  • Angrybyte Gallery-Transformation: version 1.0 only

Published 2017-09-14. Last modified 2026-06-17.