Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-24291

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.146
EPSS Ranking 94.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-24291


Contact Us

Shodan ® - All rights reserved