A vulnerability labeled as critical has been found in BestWebSoft Gallery Plugin up to 4.7.9 on WordPress. Affected by this issue is the function
gllr_save_postdata of the component Post Meta. The manipulation of the argument _gallery_order_{post_id} results in sql injection.
This vulnerability was named CVE-2026-2497. The attack may be performed from remote. There is no available exploit.