CVE-2026-12865
massReflected XSS in Photo Gallery by 10Web WordPress plugin (before 1.8.44)
Photo Gallery by 10Web, a WordPress gallery plugin, fails to escape two request parameters that are reflected into input-attribute values on its admin pages, allowing arbitrary JavaScript to execute via an auto-firing onfocus handler. An unauthenticated attacker must craft a malicious link and get a logged-in user to open it: the Shortcode-page sink can be triggered via a contributor account, while the Galleries/Albums list-page sink targets administrators and only renders on sites with more than 20 galleries or albums (the typical state of a populated install). Successful exploitation runs attacker-controlled JavaScript in the victim's authenticated session, enabling actions such as modifying content or creating rogue administrator accounts. Any WordPress site running the plugin before 1.8.44 is affected; there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at only about 0.2%.
What to do: Update Photo Gallery by 10Web to version 1.8.44 or later. Although no public exploits are known and EPSS indicates low near-term risk, patch promptly because successful attacks execute JavaScript in an administrator's session and can create rogue admin accounts. Owners who cannot update immediately should review recently created administrator accounts and content changes, and be wary of links pointing to the plugin's admin pages.
| 10Web Photo Gallery by 10Web (WordPress plugin) | before 1.8.44 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in administrator (or, for the first sink, a contributor), executes arbitrary JavaScript in the victim's authenticated session via an auto-firing onfocus handler. The Galleries/Albums sink renders only when the site has more than 20 galleries/albums (the normal state of a populated install).
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.