Impact
The Photo Gallery by 10Web – Mobile‑Friendly Image Gallery plugin for WordPress is vulnerable to Reflected XSS through the image_id parameter because the input is not sanitized and the output is not escaped. When an attacker can entice an administrative user to click a crafted link, arbitrary JavaScript will be executed in the admin context. This vulnerability is a moderate‑severity issue associated with CWE‑79.
Affected Systems
The vulnerability affects all instances of the Photo Gallery by 10Web plugin for WordPress whose version is 1.8.34 or earlier. The issue is confined to the image_id parameter used in the plugin’s admin pages; no other WordPress components are impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate risk, and the EPSS score of less than 1% shows a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because it does not require authentication and targets privileged administrators, a determined attacker can mount a successful XSS attack by sending a malicious link. The overall risk remains moderate, warranting prompt remediation.
OpenCVE Enrichment
EUVD