WordPress · 10Web Photo Gallery · CVE-2026-85652
**Name of the Vulnerable Software and Affected Versions**
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress versions prior to 1.8.45
**Description**
This issue is a time-based SQL Injection, a technique where an attacker sends a query that forces the database to wait for a specific amount of time before responding, allowing the attacker to infer information based on the response delay. The flaw exists due to insufficient escaping of user-supplied parameters and a lack of preparation in the SQL query. Authenticated attackers with author-level access or higher can inject additional SQL queries via the `album id` shortcode attribute. By storing a payload within a published post's shortcode, the attack executes when any visitor renders the post. The unsanitized value appears on both sides of a UNION query, which may double the observable time-based delay, enabling the extraction of sensitive information from the database.
**Recommendations**
Update the plugin to a version newer than 1.8.44.
As a temporary mitigation, restrict users with author-level access from editing shortcode attributes or avoid using the `album id` attribute until the update is applied.