CVE-2026-1036: Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.36 - Missing Authorization to Unauthenticated Arbitrary Comment Deletion
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deletecomment() function in all versions up to, and including, 1.8.36. This makes it possible for unauthenticated attackers to delete arbitrary image comments. Note: comments functionality is only available in the Pro version of the plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1036?
CVE-2026-1036 has been classified as a medium severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2026-1036?
To fix CVE-2026-1036, update the Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin to the latest version beyond 1.8.36.
What type of attack does CVE-2026-1036 allow?
CVE-2026-1036 allows unauthenticated users to delete arbitrary comments due to the absence of an authorization check.
Which versions of the plugin are affected by CVE-2026-1036?
CVE-2026-1036 affects versions of the Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin up to and including 1.8.36.
Who can exploit CVE-2026-1036?
CVE-2026-1036 can be exploited by any unauthenticated user capable of accessing the affected site.