CVE-2021-25041: Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)
Published Dec 6, 2021
·Updated
The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwgalbumbreadcrumb0 and shortcodeid GET parameters passed to the bwgfrontenddata AJAX action
Affected Software
1 affected component
10web Photo Gallery Wordpress<1.5.68
Remediation
Patch Available
Event History
Dec 6, 2021
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-25041.
2
What is the severity level of CVE-2021-25041?
The severity level of CVE-2021-25041 is medium, with a CVSS score of 6.1.
3
Which software is affected by CVE-2021-25041?
The Photo Gallery by 10Web WordPress plugin before 1.5.68 is affected by CVE-2021-25041.
4
What is the impact of CVE-2021-25041?
CVE-2021-25041 allows for Reflected Cross-Site Scripting (XSS) attacks.
5
How can I fix CVE-2021-25041?
To fix CVE-2021-25041, update the Photo Gallery by 10Web WordPress plugin to version 1.5.68 or later.