Update the WordPress CP Image Store with Slideshow plugin to the latest available version (at least 1.0.68)
Daniel Krohmer (Fraunhofer IESE), Shi Chen (University of Kaiserslautern) discovered and reported this SQL Injection vulnerability in WordPress CP Image Store with Slideshow Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information and creating new administrator accounts. This vulnerability has been fixed in version 1.0.68.