CVE-2026-49771: WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection.
This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Photo Gallery by 10Web Pluginto a version that resolves this vulnerability.Fixed in 1.8.42
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49771?
The severity of CVE-2026-49771 is rated high with a score of 7.6 on the CVSS scale.
How does CVE-2026-49771 affect the WordPress Photo Gallery by 10Web?
CVE-2026-49771 allows for Blind SQL Injection, which can enable attackers to manipulate the database.
How can I fix CVE-2026-49771?
To fix CVE-2026-49771, update the WordPress Photo Gallery by 10Web Plugin to version 1.8.42 or later.
What versions of the WordPress Photo Gallery by 10Web are affected by CVE-2026-49771?
CVE-2026-49771 affects the WordPress Photo Gallery by 10Web Plugin from any version up to and including 1.8.41.
What type of vulnerability is CVE-2026-49771 classified as?
CVE-2026-49771 is classified as an SQL Injection vulnerability.