Impact
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress contains an input validation flaw that allows arbitrary JavaScript code to be inserted via the unescaped 'thumb_url' parameter. When an editimage_bwg AJAX request is made, the value of this parameter is echoed back to the page without escaping, enabling a reflected XSS event. The vulnerable code is accessible only to users who possess the manage_options capability, meaning that administrative editors or site owners are the primary beneficiaries of an attacker‑supplied payload. An attacker can construct a malicious link that triggers the vulnerable request; when an authorized admin opens that link, the injected script will execute with the privileges of the victim, potentially enabling session hijacking, credential theft, defacement, or the delivery of further malware. Affected systems The vulnerability impacts all releases of the Photo Gallery by 10Web WordPress plugin up to and including version 1.8.46. Administrators or users with the manage_options capability who manage image galleries are directly affected. Risk and exploitability This flaw has a CVSS score of 6.1, indicating a moderate severity. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The primary attack vector is a crafted GET request to the editimage_bwg AJAX endpoint that contains an unsanitized thumb_url value. Because the endpoint lacks nonce verification, an attacker can trigger the vulnerability via a simple link; however, the target must have administrative privilege (manage_options) to receive the reflected payload. The risk is therefore concentrated on site administrators rather than the general user base.
Affected Systems
WordPress plugin Photo Gallery by 10Web – Mobile-Friendly Image Gallery, all versions up to and including 1.8.46
Risk and Exploitability
Moderate CVSS (6.1); EPSS not available; not listed in KEV. The most likely exploitation path is an attacker delivering a crafted URL that invokes the editimage_bwg AJAX action with an unsanitized thumb_url. The endpoint accepts GET requests without a CSRF token, and only users with the manage_options capability are impacted, meaning the attacker would need to lure an administrator or editor to click the malicious link.
OpenCVE Enrichment