Reflected Cross-Site Scripting in Photo Gallery Plugin for WordPress
CVE-2026-92974
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-92974?
The Photo Gallery by 10Web plugin for WordPress contains a reflected cross-site scripting vulnerability in the handling of the 'thumb_url' parameter. This flaw exists due to inadequate sanitization and escaping of user inputs across all versions up to and including 1.8.46. An unauthenticated attacker can exploit this vulnerability by tricking a user into clicking a crafted link, which could lead to the execution of arbitrary web scripts on the victim's machine. To execute the attack, the targeted user must possess the manage_options capability, as the editimage_bwg AJAX action checks this capability but lacks nonce verification. Consequently, the attacker can load a malicious payload through a GET request without a CSRF token, raising significant security concerns for WordPress users using the affected plugin.
Affected Version(s)
Photo Gallery by 10Web β Mobile-Friendly Image Gallery 0 <= 1.8.46