cleantalk
Vulnerabilities and Security Researches

Photo Gallery by 10Web – Mobile-Friendly Image Gallery, CVE-2019-14798

CVE, Research URL

CVE-2019-14798

Published on
Aug 09, 2019
Research Description
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
Affected versions
Min -, max 1.5.25.
Status
vulnerable