WordPress Plugin Vulnerabilities

Photo Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged Parameters

Description

The plugin does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in administrator (or, for the first sink, a contributor), executes arbitrary JavaScript in the victim's authenticated session via an auto-firing onfocus handler. The Galleries/Albums sink renders only when the site has more than 20 galleries/albums (the normal state of a populated install).

Proof of Concept

Affects Plugins

Fixed in 1.8.44

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Muni Nitish Kumar Yaddala
Submitter
Muni Nitish Kumar Yaddala
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 1 day ago)
Last Updated
2026-08-31 (about 1 day ago)

Other