WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability
CVE-2026-49771

7.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 June 2026

What is CVE-2026-49771?

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection.

This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.

Affected Version(s)

Photo Gallery by 10Web <= 1.8.41

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.