Description
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the authenticated victim holds the manage_options capability, as the editimage_bwg AJAX action performs a capability check but no nonce verification, meaning the payload can be delivered via a crafted GET request without a CSRF token.
Published: 2026-10-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress contains an input validation flaw that allows arbitrary JavaScript code to be inserted via the unescaped 'thumb_url' parameter. When an editimage_bwg AJAX request is made, the value of this parameter is echoed back to the page without escaping, enabling a reflected XSS event. The vulnerable code is accessible only to users who possess the manage_options capability, meaning that administrative editors or site owners are the primary beneficiaries of an attacker‑supplied payload. An attacker can construct a malicious link that triggers the vulnerable request; when an authorized admin opens that link, the injected script will execute with the privileges of the victim, potentially enabling session hijacking, credential theft, defacement, or the delivery of further malware. Affected systems The vulnerability impacts all releases of the Photo Gallery by 10Web WordPress plugin up to and including version 1.8.46. Administrators or users with the manage_options capability who manage image galleries are directly affected. Risk and exploitability This flaw has a CVSS score of 6.1, indicating a moderate severity. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The primary attack vector is a crafted GET request to the editimage_bwg AJAX endpoint that contains an unsanitized thumb_url value. Because the endpoint lacks nonce verification, an attacker can trigger the vulnerability via a simple link; however, the target must have administrative privilege (manage_options) to receive the reflected payload. The risk is therefore concentrated on site administrators rather than the general user base.

Affected Systems

WordPress plugin Photo Gallery by 10Web – Mobile-Friendly Image Gallery, all versions up to and including 1.8.46

Risk and Exploitability

Moderate CVSS (6.1); EPSS not available; not listed in KEV. The most likely exploitation path is an attacker delivering a crafted URL that invokes the editimage_bwg AJAX action with an unsanitized thumb_url. The endpoint accepts GET requests without a CSRF token, and only users with the manage_options capability are impacted, meaning the attacker would need to lure an administrator or editor to click the malicious link.

Generated by OpenCVE AI on October 3, 2026 at 08:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Photo Gallery by 10Web plugin to the latest patched version (any release newer than 1.8.46).
  • If an upgrade is not immediately possible, modify the plugin’s code or use a code snippet to add a nonce check to the editimage_bwg AJAX handler, ensuring that only requests signed with a valid nonce are processed.
  • Restrict access to the editimage_bwg endpoint so that only users with the manage_options capability can invoke it, and consider disabling that capability on non‑trusted user accounts.
  • Sanitize the incoming thumb_url parameter and apply output escaping before displaying it, eliminating the possibility of reflected script injection.

Generated by OpenCVE AI on October 3, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the authenticated victim holds the manage_options capability, as the editimage_bwg AJAX action performs a capability check but no nonce verification, meaning the payload can be delivered via a crafted GET request without a CSRF token.
Title Photo Gallery by 10Web <= 1.8.46 - Reflected Cross-Site Scripting via 'thumb_url' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:42.638Z

Reserved: 2026-09-17T13:26:33.966Z

Link: CVE-2026-92974

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:54.824Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:48.513

Modified: 2026-10-03T16:16:43.817

Link: CVE-2026-92974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T09:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')