CVE-2026-1036: 10web Photo Gallery By 10web – Mobile-Friendly Image Gallery
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_comment() function in all versions up to, and including, 1.8.36. This makes it possible for unauthenticated attackers to delete arbitrary image comments. Note: comments functionality is only available in the Pro version of the plugin.
Affected products
- 10web Photo Gallery By 10web – Mobile-Friendly Image Gallery: up to and including 1.8.36
Published 2026-01-22. Last modified 2026-06-17.