Medium severity4.9NVD Advisory· Published Aug 9, 2019· Updated Jun 17, 2026
CVE-2019-14798
CVE-2019-14798
Description
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.5.25
Patches
Vulnerability mechanics
References
3- www.pluginvulnerabilities.com/2019/05/14/authenticated-local-file-inclusion-lfi-vulnerability-in-photo-gallery-by-10web/nvdExploitThird Party Advisory
- wordpress.org/plugins/photo-gallery/nvdThird Party Advisory
- wpvulndb.com/vulnerabilities/9361nvdThird Party Advisory
News mentions
0No linked articles in our index yet.