Input validation vulnerability in Photo Gallery by 10Web – Mobile-Friendly Image Gallery 1.8.23

The Photo Gallery plugin for WordPress, created by 10Web, has a security issue that allows hackers to insert harmful code into web pages. This can be done through the ‘svg’ parameter and affects all versions of the plugin up to version 1.8.23. This means that anyone with access to the plugin, including administrators and contributors, can potentially inject harmful scripts into web pages that will run when a user visits the infected page.

Detected in:

Photo Gallery by 10Web – Mobile-Friendly Image Gallery fixed vulnerable versions: >= * <= 1.8.23

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.