PT-2026-84604 · 10Web · Photo Gallery
CVE-2026-12865
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
The Photo Gallery by 10Web WordPress plugin versions prior to 1.8.44
Description
Insufficient escaping of two request parameters allows an unauthenticated attacker to execute arbitrary JavaScript within the authenticated session of a logged-in administrator or contributor. This occurs when a victim opens a specially crafted link that reflects these parameters into input-attribute values on admin pages. The issue affects the Shortcode page and the Galleries/Albums list page, though the latter only triggers if the site contains more than 20 galleries or albums. The execution is achieved via an auto-firing
onfocus handler.Recommendations
Update The Photo Gallery by 10Web WordPress plugin to version 1.8.44 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Photo Gallery