CVE-2023-1427: 10web Photo Gallery

Medium severity, CVSS 4.9. EPSS: 0.8% chance of exploitation in the next 30 days.

- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.

Affected products

  • 10web Photo Gallery: before 1.8.15 (fixed in 1.8.15)

Published 2023-04-17. Last modified 2026-06-17.