PT-2026-3881 · WordPress · Photo Gallery By 10Web – Mobile-Friendly Image Gallery+1

Moose Love

·

Published

2026-01-21

·

Updated

2026-01-22

·

CVE-2026-1036

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress versions through 1.8.36
Description The software is susceptible to unauthorized data modification. A missing capability check within the delete comment() function allows unauthenticated attackers to delete arbitrary image comments. This issue is present in the Pro version of the plugin, where the comments functionality is enabled.
Recommendations Update the plugin to a version beyond 1.8.36.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1036

Affected Products

10Web – Mobile-Friendly Image Gallery
Photo Gallery By 10Web – Mobile-Friendly Image Gallery