Impact
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin contains a missing capability check on the delete_comment() function in all versions up to 1.8.36. This flaw allows an unauthenticated user to delete any image comment in the Pro version of the plugin. The ability to remove comments comes from the lack of an authorization check in the deletion routine.
Affected Systems
WordPress sites that have the 10Web Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin version 1.8.36 or earlier are affected. The Pro edition’s comment feature is present in these releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by invoking the delete_comment function without authentication, thereby deleting arbitrary comments. The overall risk is moderate but warrants prompt attention.
OpenCVE Enrichment