Junglewise Threat Intelligence

CVE-2026-85652: 10Web Photo Gallery time-based SQL injection in album_id shortcode attribute

CVE-2026-85652 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Technologies: 10Web Photo Gallery. Vendors: 10Web.

Executive brief

The Photo Gallery by 10Web is a WordPress plugin that displays image galleries on web pages. The plugin fails to properly sanitize the 'album_id' shortcode attribute, allowing authenticated WordPress authors to inject SQL commands. An attacker with author-level access can embed malicious SQL in a published post, which executes when visitors view that post, potentially exposing sensitive database information to anyone who reads the compromised page.

Technical details

The vulnerability is a time-based SQL injection in the 'album_id' shortcode parameter, present in versions up to 1.8.44. The root cause is insufficient escaping of user-supplied input and inadequate parameterization of the SQL query. An authenticated attacker with author-level access (or above) can craft a malicious shortcode attribute containing SQL payloads that are executed when the post is rendered to any visitor. The vulnerability is notable because the unsanitized value appears on both sides of a UNION query, potentially doubling the observable time-based delay and making information extraction more reliable. No patch information is provided in the advisory.

Affected products

  • 10Web Photo Gallery up to and including 1.8.44

Timeline

  • 2026-09-18: disclosed

References

Related threats