CVE-2021-25041

CVE-2021-25041: Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)

Vendor Unknown
Product Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Weakness CWE-79 · XSS
Published December 6, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

Key dates

02Disclosure timeline

December 6, 2021 CVE published
August 3, 2024 Record updated