Impact
The vulnerability allows an authenticated user with author or higher privileges to inject arbitrary SQL through the album_id shortcode attribute. The injection joins the unsanitized value on both sides of a UNION query, enabling time‑based detection and the extraction of sensitive database information. Because the payload can be stored in a published post, any visitor who renders that post triggers the malicious query, potentially exposing private data to all site visitors.
Affected Systems
The flaw affects the Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress versions up to and including 1.8.44. Any site running 10Web Photo Gallery by 10Web in these versions and that has at least one user with author or higher role is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity flaw, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. An attacker must first obtain or already possess an author‑level account; the injection is carried out by embedding a payload in the album_id attribute of a shortcode within a post, which is then executed when a visitor renders the post. No additional prerequisites such as network exposure are required beyond the authenticated access provided by the author role.
OpenCVE Enrichment