CVE-2025-0613

Publication date

2025-03-31 06:00:01

Family

WPScan

State

PUBLISHED

Description

The Photo Gallery by 10Web WordPress plugin before 1.8.34 does not sanitised and escaped comment added on images by unauthenticated users, leading to an Unauthenticated Stored-XSS attack when comments are displayed