PT-2026-3881 · WordPress · Photo Gallery By 10Web – Mobile-Friendly Image Gallery+1

Moose Love

·

Publicado

2026-01-21

·

Atualizado

2026-01-22

·

CVE-2026-1036

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress versions through 1.8.36
Description The software is susceptible to unauthorized data modification. A missing capability check within the delete comment() function allows unauthenticated attackers to delete arbitrary image comments. This issue is present in the Pro version of the plugin, where the comments functionality is enabled.
Recommendations Update the plugin to a version beyond 1.8.36.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1036

Produtos afetados

10Web – Mobile-Friendly Image Gallery
Photo Gallery By 10Web – Mobile-Friendly Image Gallery