CVE-2021-46889

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/06/2023
Last modified:
14/06/2023

Description

The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:10web:photo_gallery:*:*:*:*:*:wordpress:*:* 1.5.69 (including)