Reflected Cross-Site Scripting in Photo Gallery Plugin for WordPress
CVE-2026-92974

6.1MEDIUM

What is CVE-2026-92974?

The Photo Gallery by 10Web plugin for WordPress contains a reflected cross-site scripting vulnerability in the handling of the 'thumb_url' parameter. This flaw exists due to inadequate sanitization and escaping of user inputs across all versions up to and including 1.8.46. An unauthenticated attacker can exploit this vulnerability by tricking a user into clicking a crafted link, which could lead to the execution of arbitrary web scripts on the victim's machine. To execute the attack, the targeted user must possess the manage_options capability, as the editimage_bwg AJAX action checks this capability but lacks nonce verification. Consequently, the attacker can load a malicious payload through a GET request without a CSRF token, raising significant security concerns for WordPress users using the affected plugin.

Affected Version(s)

Photo Gallery by 10Web – Mobile-Friendly Image Gallery 0 <= 1.8.46

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

r3foxx
.