PT-2026-44217 · 10Web+1 · Photo Gallery By 10Web – Mobile-Friendly Image Gallery+1

·

CVE-2026-7048

·

Published

2026-05-27

·

Updated

2026-05-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Photo Gallery by 10Web – Mobile-Friendly Image Gallery versions prior to 1.8.41
Description An issue exists due to insufficient escaping of user-supplied parameters and lack of preparation in SQL queries. Authenticated attackers with contributor-level access or higher can perform a time-based blind SQL Injection—a technique used to extract information from a database by observing the time it takes for the server to respond to specific queries. This is achieved by embedding a malicious shortcode in a post or draft, which executes the injected SQL when the shortcode is rendered via the order by parameter.
Recommendations Update the plugin to a version later than 1.8.40. Avoid using the order by parameter in shortcodes until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7048

Affected Products

Photo Gallery By 10Web – Mobile-Friendly Image Gallery
Photo Gallery