Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection.

This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.
Published: 2026-06-04
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of special elements used in an SQL command, a classic SQL injection issue denoted by CWE-89. An attacker can exploit the Photo Gallery by 10Web plugin to trigger a blind SQL injection, which means the attacker can indirectly infer data or modify database contents without direct feedback. The lack of input validation allows attackers to craft malicious queries that can read sensitive application data, modify or delete records, and potentially gain further access to the underlying database. Such an attack compromises confidentiality and integrity of stored data and could serve as a stepping stone to more extensive system exploitation if database credentials are exposed.

Affected Systems

WordPress users running the Photo Gallery by 10Web plugin, version 1.8.41 and earlier, are affected. The vulnerability exists in all earlier releases of the plugin and affects any WordPress site that has the plugin installed.

Risk and Exploitability

This issue carries a CVSS score of 7.6, indicating high severity. The EPSS score is not available, so the precise likelihood of exploitation remains uncertain. The vulnerability is not listed in CISA's KEV catalog, suggesting there is no confirmed exploitation in the wild as of the data snapshot. Attackers would likely exploit the weakness via web requests to the gallery functionality, which makes the attack vector remote and publicly accessible. The combination of high severity and minimal mitigation steps except for an update means the risk to any vulnerable deployment is significant.

Generated by OpenCVE AI on June 4, 2026 at 11:20 UTC.

Remediation

Vendor Solution

Update the WordPress Photo Gallery by 10Web Plugin to the latest available version (at least 1.8.42).


OpenCVE Recommended Actions

  • Apply the latest plugin version 1.8.42 or newer.
  • If an update is not feasible, remove or deactivate the plugin until a patch is available.
  • Configure a Web Application Firewall or similar filtering to block suspicious SQL queries targeting the gallery endpoints.
  • Monitor database activity for unexplained reads or writes that could indicate exploitation.

Generated by OpenCVE AI on June 4, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Jun 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.
Title WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-04T09:49:49.368Z

Reserved: 2026-06-01T15:29:09.316Z

Link: CVE-2026-49771

cve-icon Vulnrichment

Updated: 2026-06-04T12:06:05.545Z

cve-icon NVD

Status : Received

Published: 2026-06-04T10:16:39.580

Modified: 2026-06-04T10:16:39.580

Link: CVE-2026-49771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-04T11:30:12Z

Weaknesses