Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function
Summary
| CVE | CVE-2024-5481 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-06-07 10:15:11 UTC |
| Updated | 2026-04-08 18:22:04 UTC |
| Description | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to cut and paste (copy) the contents of arbitrary files on the server, which can contain sensitive information, and to cut (delete) arbitrary directories, including the root WordPress directory. By default this can be exploited by administrators only. In the premium version of the plugin, administrators can give gallery edit permissions to lower level users, which might make this exploitable by users as low as contributors. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-35 | CWE-22 | CWE-35 CWE-35 Path Traversal: '.../...//'
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 6.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H |
| 3.1 | CNA | DECLARED | 6.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | 10web | Photo Gallery | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | 10web | Photo Gallery By 10Web Mobile-Friendly Image Gallery | affected 1.8.23 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| plugins.trac.wordpress.org/browser/photo-gallery/trunk/filemanager/controller.php | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Product |
| plugins.trac.wordpress.org/browser/photo-gallery/trunk/filemanager/controller.php | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Product |
| www.wordfence.com/threat-intel/vulnerabilities/id/76c38826-4d49-4204-b6b6-b01d0... | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| wordpress.org/plugins/photo-gallery | af854a3a-2127-422b-91ae-364da2661108 | wordpress.org | Product, Release Notes |
| plugins.trac.wordpress.org/browser/photo-gallery/trunk/filemanager/controller.php | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Product |
| plugins.trac.wordpress.org/changeset/3098798 | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Tobias Weißhaar (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-06-06T21:19:21.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.