First published: Mon Mar 31 2025(Updated: )
The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
10quality Post Gallery | <1.8.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0613 is classified as a moderate severity vulnerability due to its potential for an Unauthenticated Stored XSS attack.
To fix CVE-2025-0613, update the Photo Gallery by 10Web WordPress plugin to version 1.8.34 or later.
CVE-2025-0613 is associated with an Unauthenticated Stored XSS attack that exploits unsanitized comments added to images.
Users of the Photo Gallery by 10Web plugin prior to version 1.8.34 are affected by CVE-2025-0613.
Yes, CVE-2025-0613 can be exploited by unauthenticated users who can add comments on images.