CVE-2025-0613: 10web Photo Gallery

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed

Affected products

  • 10web Photo Gallery: before 1.8.34 (fixed in 1.8.34)

Published 2025-03-31. Last modified 2026-06-17.