Impact
The Photo Gallery by 10Web WordPress plugin before version 1.8.44 fails to escape two request parameters before reflecting them into input-attribute values on its admin pages. An unauthenticated attacker can craft a link that, when opened by a logged‑in administrator (or a contributor for the Shortcode sink), triggers an auto-firing onfocus handler that executes attacker‑supplied JavaScript within the victim’s authenticated session.
Affected Systems
WordPress installations running Photo Gallery by 10Web plugin version earlier than 1.8.44. The vulnerability is present on the plugin’s admin “Shortcode” page and, for sites with more than 20 galleries/albums, on the “Galleries/Albums” list page.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user to open a crafted link; no authentication is required for the attacker to send the request. Based on the description, the likely attack vector is through email, social media, or embedded links, making the risk significant for sites that use this plugin.
OpenCVE Enrichment