CVE-2026-102377: WordPress Photo Gallery by 10Web plugin <= 1.8.46 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
Affected Software
1 affected component
10web Photo Gallery by 10Web<=1.8.46
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Photo Gallery by 10Webto a version that resolves this vulnerability.Fixed in 1.8.47
Event History
Sep 30, 2026
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site using Photo Gallery by 10Web version 1.8.46 or earlier. The CVSS vector indicates the attack can be performed over the network without user interaction.
2
What impact could successful exploitation have?
The reported CVSS vector rates confidentiality, integrity, and availability impacts as high. The vulnerability is classified as PHP object injection.