CVE-2025-0613
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 31, 2025
Updated: Apr 1, 2025
Summary
CVE-2025-0613 is a stored XSS vulnerability affecting the Photo Gallery plugin by 10Web for WordPress. Before version 1.8.34, the plugin failed to properly sanitize and escape user comments added to images. As a result, unauthenticated users could inject malicious scripts into comments, which would be executed when the comments were displayed to other users, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.