nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-49771 CVE-2026-49771
HIGH
WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability
Record summary
CVE-2026-49771 has a selected CVSS score of 7.6 (high).
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 1.8.41 | affected |
References
2patchstack.comvdb entry
https://patchstack.com/database/wordpress/plugin/photo-gallery/vulnerability/wordpress-photo-gallery-by-10web-plugin-1-8-41-sql-injection-vulnerability?_s_id=cve