CVE-2025-0613Cross-site Scripting in Photo Gallery

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 31

Description

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVD10web/photo_gallery< 1.8.34

🔴Vulnerability Details

2
GHSA
GHSA-r3r3-hjgr-8x9f: The Photo Gallery by 10Web WordPress plugin before 12025-03-31
CVEList
Photo Gallery < 1.8.34 - Unauthenticated Stored XSS2025-03-31
CVE-2025-0613 — Cross-site Scripting in Photo Gallery | cvebase