The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
We have discovered 37,676 live websites that are affected by CVE-2024-5968.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 37,676 live websites (39% of Photo Gallery by 10Web install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 330 versions ( 57% of all versions) |
| 6,943 websites | |
| 4,406 websites | |
| 2,528 websites | |
| 2,069 websites | |
| 2,026 websites | |
| 2,023 websites | |
| 1,596 websites | |
| 1,101 websites | |
| 1,080 websites | |
| 935 websites |
| .com | 12,230 websites |
| .de | 2,545 websites |
| .org | 1,908 websites |
| .it | 1,716 websites |
| .ru | 1,650 websites |
| .pl | 1,526 websites |
| .nl | 983 websites |
| .cz | 941 websites |
| .co.uk | 922 websites |
| .net | 800 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.*********.com | *,*** | ||
| *********.kz | **,*** | ||
| ******.name | **,*** | ||
| *******.**.il | **,*** | ||
| ***********.org | **,*** | ||
| ***.info | **,*** | ||
| **********.***.ua | **,*** | ||
| **********.**.uk | **,*** | ||
| ********.cz | **,*** | ||
| ***.***.ph | **,*** |
FAQ