Access violation vulnerability in Photo Gallery by 10Web – Mobile-Friendly Image Gallery 1.8.19

The Photo Gallery by 10Web is a plugin used on WordPress websites to create mobile-friendly image galleries. However, it has a security vulnerability called Directory Traversal. This means that people who are logged in as administrators can change the names of any files on the website, which could lead to the takeover of the website if important files like wp-config.php are renamed. This vulnerability exists in all versions of the plugin up to 1.8.19. In the premium version, lower level users like contributors can also exploit this vulnerability if given gallery management permissions by the administrator.

Detected in:

Photo Gallery by 10Web – Mobile-Friendly Image Gallery fixed vulnerable versions: >= * <= 1.8.19

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.