The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
We have discovered 14,536 live websites that are affected by CVE-2019-14798.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 14,536 live websites (13.85% of Photo Gallery by 10Web install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 231 versions ( 37.56% of all versions) |
![]() | 3,487 websites |
![]() | 1,624 websites |
![]() | 907 websites |
![]() | 873 websites |
![]() | 857 websites |
![]() | 510 websites |
![]() | 453 websites |
![]() | 371 websites |
![]() | 348 websites |
![]() | 321 websites |
.com | 5,150 websites |
.de | 846 websites |
.ru | 755 websites |
.pl | 686 websites |
.org | 666 websites |
.it | 358 websites |
.co.uk | 338 websites |
.net | 320 websites |
.fr | 302 websites |
.nl | 292 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.kz | ![]() | **,*** | |
************.ru | ![]() | **,*** | |
***********.org | ![]() | **,*** | |
****************.org | ![]() | **,*** | |
*********.net | ![]() | ***,*** | |
****.org | ![]() | ***,*** | |
**********************.**.za | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
********.com | ![]() | ***,*** |
FAQ