Sceawere
Vulnerability Detail
CVE-2026-92974UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in 10Web Photo Gallery
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 3h ago
- Vendor
- 10web
- Product
- Photo Gallery by 10Web – Mobile-Friendly Image Gallery
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions up to, and including, 1.8.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that the authenticated victim holds the manage_options capability, as the editimage_bwg AJAX action performs a capability check but no nonce verification, meaning the payload can be delivered via a crafted GET request without a CSRF token.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-03T07:16:48.513Z",
"pubdate": "2026-10-03T07:16:48.513Z",
"executiveSummary": "The Photo Gallery by 10Web plugin for WordPress, in versions up to and including 1.8.46, is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. The flaw originates from improper input sanitization and inadequate output escaping within the 'thumb_url' parameter.\nThis vulnerability allows an unauthenticated attacker to inject and execute arbitrary JavaScript code within the context of a victim's session. The execution of the malicious script occurs when an authenticated user, specifically one possessing 'manage_options' capabilities, is deceived into interacting with a crafted, malicious link.\nThe security risk is amplified by the absence of nonce verification in the 'editimage_bwg' AJAX action. While the action correctly validates the 'manage_options' capability, the lack of CSRF protection permits an attacker to perform cross-origin requests that trigger the reflected payload.\nSuccessful exploitation could lead to unauthorized administrative actions, session hijacking, or the compromise of sensitive plugin configurations. Given that the target must be a high-privileged user, this vulnerability poses a significant risk to the integrity and confidentiality of the WordPress environment.",
"technicalDetails": "The vulnerability resides within the 'editimage_bwg' AJAX handler of the Photo Gallery by 10Web plugin. The underlying issue is a failure to sanitize the 'thumb_url' input parameter before reflecting it back into the browser's response. Because the plugin does not implement sufficient output escaping mechanisms, an attacker can supply malicious JavaScript payloads via this parameter in a crafted GET request.\nThe attack flow relies on social engineering. An unauthenticated attacker generates a specially crafted URL containing a script-based payload within the 'thumb_url' parameter. When an administrator or a user with 'manage_options' permissions clicks this link, their browser sends a request to the 'editimage_bwg' AJAX action. Although the server-side code performs a capability check to ensure the requester is authorized to manage options, it fails to validate a security nonce. This lack of CSRF protection is the critical factor that enables the request to be executed on behalf of the victim.\nUpon receiving the request, the server processes the payload and includes the unescaped 'thumb_url' content in the resulting HTML response. The browser subsequently executes the injected script, operating under the security context of the authenticated user's session. This environment allows the script to perform any action the administrator is permitted to do, including modifying site settings, creating new administrator accounts, or exfiltrating session tokens.\nThe vulnerability is explicitly tied to the interaction between the 'editimage_bwg' function and the lack of proper input handling for 'thumb_url'. As the plugin architecture does not strictly enforce input validation protocols, the application blindly trusts the input provided in the request. The exposure is effectively global, as the malicious links can be distributed via email, third-party sites, or phishing campaigns. The absence of nonce verification serves as the bypass that allows the transition from an unauthenticated request to an authorized administrative execution, as the application assumes the incoming request is intentional and legitimate based solely on the user's session cookies."
}