S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2016-10940 Scanner

CVE-2016-10940 scanner - SQL Injection (SQLi) vulnerability in ZM Gallery plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
7.2
CVSS
Description

The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

The Zm-gallery plugin for WordPress is a useful tool for websites that are designed to showcase images and galleries. The plugin offers plenty of features that make it easy to create, edit and display albums, including customizable themes, social sharing options, and a responsive design for mobile devices. Zm-gallery plugin lets website owners upload their media library, categorize images, and display galleries on any page or post on the site.

However, as with any software, vulnerabilities may exist, as in the case of the CVE-2016-10940 vulnerability found in the Zm-gallery plugin. This vulnerability applies to version 1.0 of the plugin and is caused by insufficient filtering of user inputs, thus allowing attackers to manipulate the order parameter in the plugin and execute SQL injections.

Exploiting the CVE-2016-10940 vulnerability can lead to serious consequences for website owners. By manipulating the user input, an attacker could gain unauthorized access to the website's database, extract and steal sensitive information, and even take control of the entire website and its functionalities. This could impact the site's reputation, user trust, and cause significant financial losses.

Thanks to the pro features of the S4E platform, website administrators can easily and quickly learn about vulnerabilities in their digital assets. Our platform offers a comprehensive vulnerability assessment that covers a wide range of web applications, including WordPress plugins like Zm-gallery. By using our platform, you can stay on top of the latest security threats and take proactive measures to protect your website and user data.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website administrators can take several precautions, including:

  • Updating the Zm-gallery plugin to the latest version
  • Using a web application firewall (WAF) to filter and block malicious SQL injection attempts
  • Implementing input validation and sanitization techniques to filter user input
  • Applying least privilege access control principles to limit user permissions
  • Regularly monitoring website logs and activities for suspicious behavior

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-10940 scanner - SQL Injection (SQLi) vulnerability in ZM Gallery plugin for WordPress | S4E