The 10Web Photo Gallery plugin up to and including 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
10web photo gallery |