CVE-2025-0613: Photo Gallery < 1.8.34 - Unauthenticated Stored XSS
The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0613?
CVE-2025-0613 is classified as a moderate severity vulnerability due to its potential for an Unauthenticated Stored XSS attack.
How do I fix CVE-2025-0613?
To fix CVE-2025-0613, update the Photo Gallery by 10Web WordPress plugin to version 1.8.34 or later.
What type of attack is associated with CVE-2025-0613?
CVE-2025-0613 is associated with an Unauthenticated Stored XSS attack that exploits unsanitized comments added to images.
Who is affected by CVE-2025-0613?
Users of the Photo Gallery by 10Web plugin prior to version 1.8.34 are affected by CVE-2025-0613.
Can CVE-2025-0613 be exploited by unauthenticated users?
Yes, CVE-2025-0613 can be exploited by unauthenticated users who can add comments on images.