Impact
Unauthenticated Cross Site Scripting allows an attacker to inject malicious scripts into the common interface of the plugin. A script embedded in the gallery display or configuration can execute in the context of site visitors, potentially stealing session data, defacing the site, or redirecting users to phishing pages. The vulnerability arises from insufficient input sanitization, which corresponds to a classic XSS weakness.
Affected Systems
The issue affects the WordPress Photo Gallery by 10Web plugin for all releases up to and including 1.8.47. Any WordPress installation using this plugin version and not yet updated is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk, and the vulnerability requires no authentication, meaning any remote user can craft a request that triggers the injection. Because EPSS data is unavailable, the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog, but the potential impact on user privacy and site integrity remains significant. An attacker can easily exploit the flaw through the web interface, making it a viable target for automated attacks.
OpenCVE Enrichment