Medium severity6.1NVD Advisory· Published Sep 8, 2019· Updated Jun 17, 2026
CVE-2019-16118
CVE-2019-16118
Description
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/photo-gallerydescription
- Range: <1.5.35
Patches
Vulnerability mechanics
References
5- plugins.trac.wordpress.org/changeset/2150912/photo-gallery/trunk/admin/controllers/Options.phpnvdPatch
- plugins.trac.wordpress.org/changeset/2150912/photo-gallery/trunk/js/bwg.jsnvdPatch
- packetstormsecurity.com/files/154433/WordPress-Photo-Gallery-1.5.34-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- wpvulndb.com/vulnerabilities/9872nvdThird Party Advisory
- wordpress.org/plugins/photo-gallery/nvdProduct
News mentions
0No linked articles in our index yet.