critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0169 Scanner

CVE-2022-0169 scanner - SQL Injection vulnerability in Photo Gallery by 10Web

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0169
9.8
CVSS

The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
AFFECTED< 1.6.0SAFE ✓≥ 1.6.0
Updated Aug 22, 2026View on NVD →
Detail

Photo Gallery by 10Web is a versatile WordPress plugin designed for creating and managing photo galleries and albums on WordPress websites. It is widely used by web developers, photographers, and bloggers to showcase visual content in an organized and aesthetically pleasing manner. The plugin offers a range of customizable options, including various layouts, lightbox effects, and image transition styles, making it a popular choice for enhancing website visual content.

This critical security flaw enables attackers to manipulate SQL queries by injecting malicious SQL code via the bwg_tag_id_bwg_thumbnails_0 parameter. The vulnerability can be exploited without authentication, allowing attackers to potentially access sensitive database information, modify database content, or compromise the website's integrity and availability. The issue was addressed in version 1.6.0 of the plugin, which introduced proper input validation and sanitization to mitigate the risk.

Exploiting this vulnerability could lead to a wide range of adverse impacts, including unauthorized disclosure of sensitive data, manipulation or deletion of database content, and complete compromise of the WordPress site. It could also be used as a foothold for further attacks against the site's users or infrastructure.

By leveraging the comprehensive security scanning services offered by S4E, users can identify and mitigate vulnerabilities like the SQL Injection flaw in Photo Gallery by 10Web. Our platform provides detailed insights into potential vulnerabilities, offering actionable recommendations for enhancing your website's security posture. Joining S4E enables you to benefit from our expertise in cybersecurity, helping protect your digital assets from emerging threats.

 

References

Solution Advice
  1. Immediately update the Photo Gallery by 10Web plugin to version 1.6.0 or later.
  2. Regularly update all WordPress plugins, themes, and the core installation to their latest versions.
  3. Utilize security plugins and tools to monitor and block suspicious activities.
  4. Implement website firewalls and intrusion detection systems to safeguard against common web vulnerabilities.
  5. Conduct regular security audits and penetration testing to identify and address potential vulnerabilities.
  6. Educate website administrators and users on best practices for web security to prevent compromise.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.