Executive brief
Photo Gallery by 10Web is a popular WordPress plugin used to create and manage image galleries. A security vulnerability in this plugin allows an attacker with high-level administrative or contributor access to perform unauthorized database queries. This could lead to the theft of sensitive information from the website's database or impact the site's overall availability.
Technical details
A blind SQL injection vulnerability exists in the 10Web Photo Gallery plugin for WordPress due to improper neutralization of special elements in SQL commands (CWE-89). The flaw is present in versions up to and including 1.8.41. An attacker with high-level privileges (such as a Contributor or higher) can exploit this over the network without user interaction to execute arbitrary SQL queries. While the CVSS score is 7.6, the requirement for high privileges reduces the likelihood of mass exploitation. The issue has been addressed in version 1.8.42.
Affected products
- 10Web Photo Gallery by 10Web up to 1.8.41
Timeline
- 2026-05-06: other: Reported by researcher daroo
- 2026-06-04: advisory: Published by Patchstack and NVD
- 2026-06-04: patched: Fixed in version 1.8.42