CVE-2019-14798

The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.


We have discovered 14,536 live websites that are affected by CVE-2019-14798.

Test my site




Affected Software

Product  Photo Gallery by 10Web
Category Wordpress Plugins
Vulnerable Domains14,536 live websites (13.85% of Photo Gallery by 10Web install base)
Vulnerable Versions
  • from 0 before 1.5.25
Vulnerable Versions Count231 versions ( 37.56% of all versions)



Details

  • Published - Aug 9, 2019
  • Updated - Aug 5, 2024

CVE-2019-14798 usage by Country

United States3,487 websites



Germany1,624 websites
Russia907 websites
Poland873 websites
France857 websites
GB510 websites
Italy453 websites
Japan371 websites
Netherlands348 websites
Hungary321 websites

CVE-2019-14798 usage by TLD

.com5,150 websites
.de846 websites
.ru755 websites
.pl686 websites
.org666 websites
.it358 websites
.co.uk338 websites
.net320 websites
.fr302 websites
.nl292 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2019-14798

Top websites that are affected by CVE-2019-14798. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.kz Kazakhstan**,***
************.ru Russia**,***
***********.org United States**,***
****************.org United States**,***
*********.net Italy***,***
****.org United States***,***
**********************.**.za United States***,***
***********.com United States***,***
**********.com United States***,***
********.com United States***,***
See full domain list

FAQ

A total of 14,536 websites have been identified as vulnerable to CVE-2019-14798, discovered through global website indexing conducted by WebTechSurvey.
Photo Gallery by 10Web is susceptible to CVE-2019-14798 vulnerability.
Photo Gallery by 10Web versions before 1.5.25 are vulnerable to CVE-2019-14798.
Version 1.5.25 of Photo Gallery by 10Web addresses the CVE-2019-14798 security vulnerability.