CVE-2021-46889: XSS
The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via themeid for bwgfrontenddata. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46889?
CVE-2021-46889 is a vulnerability in the 10Web Photo Gallery plugin for WordPress that allows XSS attacks through the theme_id parameter.
How does CVE-2021-46889 affect the 10Web Photo Gallery plugin?
CVE-2021-46889 allows XSS attacks in the 10Web Photo Gallery plugin version 1.5.69 and prior versions.
What is the severity of CVE-2021-46889?
CVE-2021-46889 has a severity rating of 6.1 (medium).
How can I fix CVE-2021-46889 in the 10Web Photo Gallery plugin?
To fix CVE-2021-46889, it is recommended to update the 10Web Photo Gallery plugin to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2021-46889?
More information about CVE-2021-46889 can be found at the following reference link: [CVE-2021-46889 Reference](https://packetstormsecurity.com/files/162227/WordPress-Photo-Gallery-1.5.69-Cross-Site-Scripting.html)