Executive brief
The Photo Gallery by 10Web is a popular WordPress plugin for displaying image galleries. An authenticated attacker with Author-level access or higher can inject malicious JavaScript code into gallery shortcodes that will execute in the browsers of any user viewing the affected page, potentially stealing session data or defacing content.
Technical details
The plugin is vulnerable to Stored Cross-Site Scripting (XSS) via insufficient input sanitization and output escaping of shortcode attributes. An authenticated attacker with Author-level access or above can inject arbitrary JavaScript into shortcode parameters, which is stored in the page and executed when users view that page. The vulnerability affects all versions up to and including 1.8.44. This is a post-authentication attack that requires Author-level or higher privileges on the WordPress site.
Affected products
- 10Web Photo Gallery by 10Web up to and including 1.8.44
Timeline
- 2026-09-17: disclosed