CVE-2025-0613: 10web Photo Gallery
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed
Affected products
- 10web Photo Gallery: before 1.8.34 (fixed in 1.8.34)
Published 2025-03-31. Last modified 2026-06-17.