Junglewise Threat Intelligence

CVE-2026-7048: 10Web Photo Gallery SQL injection in order_by parameter

CVE-2026-7048 · Severity: medium · CVSS 6.5 · Published 2026-05-28

Technologies: 10Web Photo Gallery. Vendors: 10Web.

Executive brief

A popular WordPress plugin used for creating image galleries is vulnerable to a security flaw that could allow unauthorized data access. An attacker with basic contributor-level access can use this vulnerability to extract sensitive information from the website's database. This could lead to the exposure of user data or internal site configurations, potentially compromising the entire website.

Technical details

The Photo Gallery by 10Web plugin for WordPress is vulnerable to time-based blind SQL Injection due to insufficient escaping of the 'order_by' parameter and a lack of SQL query preparation. Authenticated attackers with contributor-level permissions or higher can exploit this by embedding a malicious shortcode into a post or draft. When the shortcode is rendered, the injected SQL commands execute against the database. This allows for the extraction of sensitive data using time-based inference techniques. The vulnerability affects all versions up to and including 1.8.40.

Affected products

  • 10Web Photo Gallery by 10Web – Mobile-Friendly Image Gallery Up to and including 1.8.40

Timeline

  • 2026-05-28: disclosed: Advisory published by Wordfence and NVD

References

Related threats