CyberRota Analysis
AI-GeneratedNGG Smart Image Search versions prior to 4.0.0 are vulnerable to an unauthenticated SQL injection, allowing attackers to execute arbitrary SQL queries on the database. This critical vulnerability could lead to data exposure, manipulation, or deletion, severely impacting the integrity and confidentiality of the affected systems. Organizations using this plugin should prioritize immediate updates to version 4.0.0 or later to mitigate potential exploitation.
CVE
CVE-2026-73185
Severity
CRITICAL
CVSS
9.3
EPSS
0.24%
Original NVD Description
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.