Junglewise Threat Intelligence

CVE-2026-86311: Photo Gallery by 10Web stored cross-site scripting in shortcode attributes

CVE-2026-86311 · Severity: medium · CVSS 6.4 · Published 2026-09-17

Executive brief

The Photo Gallery by 10Web is a popular WordPress plugin for displaying image galleries. An authenticated attacker with Author-level access or higher can inject malicious JavaScript code into gallery shortcodes that will execute in the browsers of any user viewing the affected page, potentially stealing session data or defacing content.

Technical details

The plugin is vulnerable to Stored Cross-Site Scripting (XSS) via insufficient input sanitization and output escaping of shortcode attributes. An authenticated attacker with Author-level access or above can inject arbitrary JavaScript into shortcode parameters, which is stored in the page and executed when users view that page. The vulnerability affects all versions up to and including 1.8.44. This is a post-authentication attack that requires Author-level or higher privileges on the WordPress site.

Affected products

  • 10Web Photo Gallery by 10Web up to and including 1.8.44

Timeline

  • 2026-09-17: disclosed

References

Related threats