CVE-2026-32330: WordPress Photo Gallery by 10Web plugin <= 1.8.37 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Cross Site Request Forgery.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.37.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32330?
CVE-2026-32330 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can potentially lead to unauthorized actions being performed on behalf of an authenticated user.
How do I fix CVE-2026-32330?
To mitigate CVE-2026-32330, it is recommended to update the Photo Gallery by 10Web plugin to the latest version beyond 1.8.37.
Who is affected by CVE-2026-32330?
CVE-2026-32330 affects users of the Photo Gallery by 10Web plugin version 1.8.37 and earlier.
What types of attacks can CVE-2026-32330 enable?
CVE-2026-32330 can allow attackers to perform unauthorized actions on the website if they trick an authenticated user into clicking a malicious link or button.
Is CVE-2026-32330 patched in later versions of the plugin?
Yes, CVE-2026-32330 has been resolved in versions of the Photo Gallery by 10Web plugin released after 1.8.37.