VYPR
Medium severity5.9NVD Advisory· Published Oct 6, 2024· Updated Apr 23, 2026

CVE-2024-44043

CVE-2024-44043

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.27.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in 10Web Photo Gallery plugin for WordPress allows attackers with low privileges to inject malicious scripts.

The 10Web Photo Gallery plugin for WordPress (versions up to and including 1.8.27) contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation. This allows an authenticated user with low-level privileges to inject arbitrary JavaScript or HTML into gallery pages.

To exploit this vulnerability, an attacker must have contributor-level access or higher to the WordPress site. The injected payload is stored on the server and executed in the browsers of other users, including administrators and visitors, when they view the affected gallery pages. User interaction is required for the initial injection, but subsequent execution is automatic.

Successful exploitation enables an attacker to perform actions such as redirecting visitors to malicious sites, displaying advertisements, or stealing session cookies. This type of vulnerability is commonly used in mass-exploit campaigns targeting multiple WordPress sites simultaneously [1].

The vendor released version 1.8.28 to fix the issue. Users are strongly advised to update the plugin immediately. For sites that cannot be updated immediately, temporary mitigation includes restricting contributor-level access and using a web application firewall [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.