CVE-2016-11018 | Huge-IT gallery-images Plugin up to 1.8.9/1.9.0 on WordPress Header huge_it_image_gallery_ajax_callback Client-Ip/X-Forwarded-For sql injection
A vulnerability classified as critical has been found in Huge-IT gallery-images Plugin up to 1.8.9/1.9.0 on WordPress. This affects the function huge_it_image_gallery_ajax_callback of the component Header Handler. The manipulation of the argument Client-Ip/X-Forwarded-For leads to sql injection.
This vulnerability is uniquely identified as CVE-2016-11018. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.