Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.38.
Published: 2026-02-19
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Update
AI Analysis

Impact

The vulnerability is a stored Cross‑Site Scripting flaw in the WordPress Photo Gallery by 10Web plugin. User input fed to the photo gallery page is not properly escaped, allowing an attacker to inject arbitrary JavaScript that is later served to any user who views the gallery. This flaw is identified as CWE‑79 and carries a CVSS score of 5.9. An attacker who can insert malicious code would gain the ability to execute client‑side scripts, potentially hijacking user sessions or defacing content, without having direct control over the server.\n

Affected Systems

Any installation of the 10Web Photo Gallery plugin for WordPress with a version of 1.8.38 or earlier is affected. The vulnerability is present from the earliest releases through to and including 1.8.38.\n

Risk and Exploitability

The risk rating is moderate due to the CVSS score of 5.9, but the Probability of Exploitation according to the EPSS is very low (<1%). The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a web‑based form or interface that allows an attacker with sufficient privileges (such as an administrator or a user with gallery‑creation rights) to inject malicious script into a gallery field. Once stored, the script executes for any visitor to the affected gallery page, with full access to the browser context but not to the underlying server. The low exploitation likelihood reflects the need for the attacker to have some level of access to the WordPress backend or gallery management interface.

Generated by OpenCVE AI on April 16, 2026 at 00:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the 10Web Photo Gallery plugin to version 1.8.39 or later, which removes the stored‑XSS vulnerability.
  • If an upgrade is not immediately possible, disable the Photo Gallery plugin until the patch is applied.
  • Apply input validation to any gallery title or description fields, ensuring that all user input is properly escaped before rendering in HTML contexts.

Generated by OpenCVE AI on April 16, 2026 at 00:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.37. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.38.
Title WordPress Photo Gallery by 10Web plugin <= 1.8.37 - Cross Site Scripting (XSS) vulnerability WordPress Photo Gallery by 10Web plugin <= 1.8.38 - Cross Site Scripting (XSS) vulnerability

Fri, 20 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared 10web
10web photo Gallery
Wordpress
Wordpress wordpress
Vendors & Products 10web
10web photo Gallery
Wordpress
Wordpress wordpress

Thu, 19 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.37.
Title WordPress Photo Gallery by 10Web plugin <= 1.8.37 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

10web Photo Gallery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:15:02.268Z

Reserved: 2026-02-19T09:51:48.837Z

Link: CVE-2026-27360

cve-icon Vulnrichment

Updated: 2026-02-20T17:17:09.579Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T21:18:32.950

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-27360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T00:15:18Z

Weaknesses