CVE-2019-14798: 10web Photo Gallery
Medium severity, CVSS 4.9. EPSS: 4.4% chance of exploitation in the next 30 days.
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
Affected products
- 10web Photo Gallery: before 1.5.25 (fixed in 1.5.25)
Published 2019-08-09. Last modified 2026-06-17.