PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-85652 10web CVE debrief

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44. Authenticated attackers with author-level access can inject SQL queries, potentially extracting sensitive database information. This vulnerability allows attackers to append additional SQL queries to existing queries, which can be used to extract sensitive information from the database. The payload can be stored in a published post's shortcode attribute and executed when any visitor renders the post. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. WordPress and

Vendor
10web
Product
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-09-18
Advisory published
2026-09-18
Advisory updated
2026-09-18

Who should care

WordPress administrators, security teams, and users with author-level access or higher should assess exposure and apply patches. Additionally, users with elevated access levels, such as administrators, should verify if author-level access or higher is present in the WordPress environment and review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

CVE-2026-85652 is a time-based SQL Injection vulnerability in the Photo Gallery plugin for WordPress. Authenticated attackers with author-level access can inject SQL queries, potentially extracting sensitive database information. WordPress administrators and security teams should assess exposure and apply patches.

  • Potential extraction of sensitive database information by authenticated attackers.
  • Possible disruption of database operations due to injected SQL queries.
  • Increased risk of data breaches due to insufficient escaping of user-supplied parameters.
  • Need for verification of plugin versions and user access levels to prevent exploitation.

Technical summary

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via the 'album_id' Shortcode Attribute. This allows authenticated attackers with author-level access to append additional SQL queries to existing queries, potentially extracting sensitive information from the database. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The payload can be stored in a published post's shortcode attribute and executed when any visitor renders the post. The vulnerability affects all versions up to, and including, 1.8.44.

Defensive priority

Medium priority for WordPress administrators and security teams to assess exposure and apply patches.

Recommended defensive actions

  • Assess exposure by checking if the Photo Gallery plugin version is 1.8.44 or earlier.
  • Verify if author-level access or higher is present in the WordPress environment.
  • Apply patches or updates to the plugin as soon as available.
  • Monitor for suspicious SQL query activity in the WordPress database.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability allows authenticated attackers with author-level access to inject SQL queries via the 'album_id' Shortcode Attribute. The payload can be stored in a published post's shortcode attribute and executed when any visitor renders the post.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-85652 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-85652

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-85652 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85652

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.