← Back to CVE List
Vulnerability Analysis
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

CVE-2026-86311

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Cross-Site Scripting (XSS) No Active Exploit Signals
CVSS Base Score
6.4
MEDIUM
Exploitability:3.2
Impact Score:2.8
Temporal Score:-
EPSS:0.19%

Threat Intelligence Signals

CISA KEV
No
KEV Date Added
Ransomware Use
KEV Due Date
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
0.195%
EPSS Percentile
9.5th pct
GitHub Severity
MODERATE
SSVC Exploitation
None
SSVC Automatable
No
Vulnerability Class
Cross-Site Scripting (XSS)

Identity & Timeline

Status-
Assigning Authority-
Discovered Via-
Record Completeness-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD