10Web Photo Gallery by 10Web
cpe:2.3:a:10web:photo_gallery:*:*:*:*:wordpress:*:*
- <= 1.8.36
A vulnerability exists in the Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress, in all versions through 1.8.36. The issue arises from a missing capability check in the delete_comment() function, allowing unauthenticated attackers to delete arbitrary image comments. This vulnerability affects only the Pro version of the plugin, where the comments feature is available.
Exploitation of this vulnerability allows for the unauthorized deletion of image comments, potentially disrupting user interactions and feedback on the associated images.
Users are advised to update the plugin to version 1.8.37 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.