Description
Unauthenticated Cross Site Scripting (XSS) in Photo Gallery by 10Web <= 1.8.47 versions.
Published: 2026-10-10
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

Unauthenticated Cross Site Scripting allows an attacker to inject malicious scripts into the common interface of the plugin. A script embedded in the gallery display or configuration can execute in the context of site visitors, potentially stealing session data, defacing the site, or redirecting users to phishing pages. The vulnerability arises from insufficient input sanitization, which corresponds to a classic XSS weakness.

Affected Systems

The issue affects the WordPress Photo Gallery by 10Web plugin for all releases up to and including 1.8.47. Any WordPress installation using this plugin version and not yet updated is vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity risk, and the vulnerability requires no authentication, meaning any remote user can craft a request that triggers the injection. Because EPSS data is unavailable, the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog, but the potential impact on user privacy and site integrity remains significant. An attacker can easily exploit the flaw through the web interface, making it a viable target for automated attacks.

Generated by OpenCVE AI on October 10, 2026 at 20:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Photo Gallery by 10Web to a version newer than 1.8.47, following the vendor’s official release notes or patch instructions.
  • If an immediate update is not possible, disable the plugin entirely or prevent it from rendering gallery content until the upgrade can be applied.
  • Verify that any custom gallery or shortcode usage performs proper output escaping, and consider restricting the input fields to whitelisted characters as an additional temporary safeguard.

Generated by OpenCVE AI on October 10, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Photo Gallery by 10Web <= 1.8.47 versions.
Title WordPress Photo Gallery by 10Web plugin <= 1.8.47 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:16.054Z

Reserved: 2026-04-29T09:05:14.679Z

Link: CVE-2026-42715

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:36.513

Modified: 2026-10-10T20:16:36.513

Link: CVE-2026-42715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T21:00:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')