cleantalk
Vulnerabilities and Security Researches

Photo Gallery by 10Web – Mobile-Friendly Image Gallery, faac0458cd9a2cbf17c4d4476ecea79a7e18905a

Published on
Jul 19, 2021
Research Description
Photo Gallery by 10Web &#8211; Mobile-Friendly Image Gallery [photo-gallery] < 1.5.79 Photo Gallery by 10Web <= 1.5.78 - Stored Cross-Site Scripting via Uploaded SVG The Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.78 due to insufficient sanitization and escaping on SVG uploads. This makes it possible for low-level authenticated attackers, such as authors, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.5.79.
Status
vulnerable