CVE-2022-0169: 10web Photo Gallery

Critical severity, CVSS 9.8. EPSS: 74.6% chance of exploitation in the next 30 days.

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

Affected products

  • 10web Photo Gallery: before 1.6.0 (fixed in 1.6.0)

Published 2022-03-14. Last modified 2026-06-17.