PatchSiren cyber security CVE debrief
CVE-2026-42715 10Web CVE debrief
Unauthenticated Cross Site Scripting (XSS) in Photo Gallery by 10Web <= 1.8.47 versions. This vulnerability allows attackers to inject malicious scripts into websites using the affected plugin, potentially leading to unauthorized script injection and impact on site integrity and user trust. Defenders should assess exposure and apply patches or mitigations.
- Vendor
- 10Web
- Product
- Photo Gallery by 10Web
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for WordPress installations with the Photo Gallery by 10Web plugin should assess exposure and apply patches or mitigations.
Why it matters
Defenders should prioritize verifying exposure and applying patches or mitigations for Unauthenticated Cross Site Scripting (XSS) in Photo Gallery by 10Web <= 1.8.47 versions.
- Potential for unauthorized script injection
- Possible impact on site integrity and user trust
Technical summary
The vulnerability is an Unauthenticated Cross Site Scripting (XSS) issue in Photo Gallery by 10Web versions <= 1.8.47. It allows attackers to inject malicious scripts into websites using the affected plugin. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent XSS
Defensive priority
Defenders should prioritize verifying exposure and applying patches or mitigations.
Recommended defensive actions
- Verify exposure of Photo Gallery by 10Web versions <= 1.8.47
- Apply patches or mitigations for vulnerable versions
- Monitor for potential XSS attacks
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42715 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42715
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42715 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42715
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.