PT-2026-84604 · 10Web · Photo Gallery

CVE-2026-12865

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Photo Gallery by 10Web WordPress plugin versions prior to 1.8.44
Description Insufficient escaping of two request parameters allows an unauthenticated attacker to execute arbitrary JavaScript within the authenticated session of a logged-in administrator or contributor. This occurs when a victim opens a specially crafted link that reflects these parameters into input-attribute values on admin pages. The issue affects the Shortcode page and the Galleries/Albums list page, though the latter only triggers if the site contains more than 20 galleries or albums. The execution is achieved via an auto-firing onfocus handler.
Recommendations Update The Photo Gallery by 10Web WordPress plugin to version 1.8.44 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12865

Affected Products

Photo Gallery