Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8715 | The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed |
Tue, 13 May 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
10web
10web photo Gallery |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:10web:photo_gallery:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
10web
10web photo Gallery |
Mon, 31 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Mar 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Photo Gallery < 1.8.34 - Unauthenticated Stored XSS |
Mon, 31 Mar 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-31T14:59:55.246Z
Reserved: 2025-01-21T07:29:07.408Z
Link: CVE-2025-0613
Updated: 2025-03-31T12:47:34.701Z
Status : Analyzed
Published: 2025-03-31T06:15:29.463
Modified: 2025-05-13T13:29:46.120
Link: CVE-2025-0613
No data.
OpenCVE Enrichment
No data.
EUVD