S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24291 Scanner

CVE-2021-24291 scanner - Cross-Site Scripting (XSS) vulnerability in Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24291
6.1
CVSS

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Photo Gallery by 10Web – Mobile-Friendly Image Galleryby Photo Gallery Team
AFFECTED< 1.5.69SAFE ✓≥ 1.5.69
Updated Aug 21, 2026View on NVD →
Detail

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin is a popular WordPress plugin used to display images on websites. This plugin allows users to create stunning responsive galleries, customize them to fit their website theme or brand, and easily manage their image collections. With its user-friendly interface and numerous functionalities, this plugin has gained widespread adoption among website owners looking to showcase their visual content.

However, recently a vulnerability, CVE-2021-24291, was detected in this plugin. This vulnerability is a Reflected Cross-Site Scripting (XSS) issue that occurs via the gallery_id, tag, album_id, and _id GET parameters that are passed to the bwg_frontend_data AJAX action. This vulnerability can allow attackers to inject malicious code into a website's HTML or JavaScript code, which can lead to a range of serious security issues.

When exploited, this vulnerability can cause significant harm to websites. Attackers can use XSS attacks to steal sensitive user information, modify site content, steal login credentials, and even spread malware. This can ultimately ruin a website's reputation and lead to financial losses.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. This platform offers comprehensive vulnerability scanning and reporting, which can help website owners detect potential vulnerabilities early on and take action to prevent them from being exploited. With s4e.io, website owners can protect their assets and keep their business safe from cyber threats.

 

REFERENCES

Solution Advice

There are several precautions that website owners can take to protect against this vulnerability. These include:

  • Updating the Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin to the latest version that has fixed the vulnerability.
  • Disabling the bwg_frontend_data AJAX action until the plugin is updated.
  • Filtering any user-supplied data that is passed to the AJAX actions.
  • Implementing a web application firewall (WAF) to detect and block XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24291 scanner - Cross-Site Scripting (XSS) vulnerability in Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress | S4E