CVE-2026-2497

Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, 4.7.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The `gllr_save_postdata()` function stores unsanitized array keys from `$_POST` directly into post meta, which are later used in SQL queries without prepared statements. This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 2,041 live websites that are affected by CVE-2026-2497.

Run a Free Instant Scan




Affected Software

Product  Gallery for WordPress
Category Wordpress Plugins
Vulnerable Domains2,041 live websites (99% of Gallery for WordPress install base)
Vulnerable Versions
  • from 0 through 4.7.9
Vulnerable Versions Count21 versions ( 91% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Farrukh Ziyaev (finder)

Website Distribution by Country

Number of websites using CVE-2026-2497
United States448 websites



Germany265 websites
Russia133 websites
GB115 websites
Netherlands105 websites
France76 websites
Poland70 websites
Italy62 websites
Czech Republic53 websites
India51 websites

Website Distribution by TLD

Number of websites using CVE-2026-2497
.com621 websites
.de181 websites
.org119 websites
.ru117 websites
.nl108 websites
.co.uk75 websites
.net54 websites
.pl49 websites
.cz47 websites
.ch45 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-2497

Top websites that are affected by CVE-2026-2497. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.org Russia***,***
****************.org United States***,***
*************.com United States***,***
**********************.com United States***,***
*************.com United States***,***
***********.org Italy***,***
*****.***.br Brazil*,***,***
*************.com Switzerland*,***,***
***************.de Germany*,***,***
*******************.org *,***,***
See full domain list

FAQ

CVE-2026-2497 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Gallery for WordPress
A total of 2,041 websites have been identified as vulnerable to CVE-2026-2497, based on global website indexing conducted by WebTechSurvey.
The Gallery for WordPress is affected by the CVE-2026-2497 vulnerability.
Gallery for WordPress versions up to and including 4.7.9 are vulnerable to CVE-2026-2497.