Input validation vulnerability in Photo Gallery by 10Web – Mobile-Friendly Image Gallery 1.5.78

The Photo Gallery plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This affects versions up to, and including, 1.5.78. The plugin does not properly filter and secure the uploads of SVG files, which makes it possible for attackers with low-level access, like authors, to inject malicious web scripts into pages. Every time a user visits an infected page, the malicious scripts will run.

Detected in:

Photo Gallery by 10Web – Mobile-Friendly Image Gallery fixed vulnerable versions: >= * <= 1.5.78

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.