Executive brief
The Photo Gallery by 10Web is a WordPress plugin that displays image galleries on web pages. The plugin fails to properly sanitize the 'album_id' shortcode attribute, allowing authenticated WordPress authors to inject SQL commands. An attacker with author-level access can embed malicious SQL in a published post, which executes when visitors view that post, potentially exposing sensitive database information to anyone who reads the compromised page.
Technical details
The vulnerability is a time-based SQL injection in the 'album_id' shortcode parameter, present in versions up to 1.8.44. The root cause is insufficient escaping of user-supplied input and inadequate parameterization of the SQL query. An authenticated attacker with author-level access (or above) can craft a malicious shortcode attribute containing SQL payloads that are executed when the post is rendered to any visitor. The vulnerability is notable because the unsanitized value appears on both sides of a UNION query, potentially doubling the observable time-based delay and making information extraction more reliable. No patch information is provided in the advisory.
Affected products
- 10Web Photo Gallery up to and including 1.8.44
Timeline
- 2026-09-18: disclosed