Authenticated Local File Inclusion Vulnerability in 10Web Photo Gallery Plugin for WordPress

Authenticated Local File Inclusion Vulnerability in 10Web Photo Gallery Plugin for WordPress

CVE-2019-14798 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:N/A:N

The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.

Learn more about our Wordpress Pen Testing.