CVE-2026-92974
published 2026-10-03CVE-2026-92974: The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.23%
12.3th percentile
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the authenticated victim holds the manage_options capability, as the editimage_bwg AJAX action performs a capability check but no nonce verification, meaning the payload can be delivered via a crafted GET request without a CSRF token.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 10web | photo_gallery_by_10web_mobile-friendly_image_gallery | <= 1.8.46 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
10Web Photo Gallery by 10Web Plugin up to 1.8.46 on WordPress AJAX Action editimage_bwg thumb_url cross site scripting
vuldb·2026-10-03·CVSS 6.1
CVE-2026-92974 [MEDIUM] 10Web Photo Gallery by 10Web Plugin up to 1.8.46 on WordPress AJAX Action editimage_bwg thumb_url cross site scripting
A vulnerability was found in 10Web Photo Gallery by 10Web Plugin up to 1.8.46 on WordPress. It has been rated as problematic. This issue affects the function editimage_bwg of the component AJAX Action Handler. This manipulation of the argument thumb_url causes cross site scripting.
The identification of this vulnerability is CVE-2026-92974. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.
ghsa_unreviewed·2026-10-03
CVE-2026-92974 [MEDIUM] CWE-79 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the authenticated victim holds the manage_options capability, as the editimage_bwg AJAX action performs a capability check but no nonce verification, meaning the payload can be delivered via a crafted GET request without a CSRF token.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.46/admin/views/Editimage.php#L273https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.46/admin/views/Editimage.php#L93https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.46/framework/WDWLibrary.php#L18https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.46/photo-gallery.php#L910https://plugins.trac.wordpress.org/changeset?reponame=&old=3716530%40photo-gallery&new=3716530%40photo-galleryhttps://www.wordfence.com/threat-intel/vulnerabilities/id/29c33526-3a60-45ab-95ef-22c78b310f74?source=cve
2026-10-03
Published