CVE-2017-14125: Wpdevart Responsive Image Gallery Gallery Album
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.
Affected products
- Wpdevart Responsive Image Gallery Gallery Album: up to and including 1.2.0
Published 2017-09-25. Last modified 2026-06-17.