CVE-2026-85652 Overview
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress contains a time-based SQL Injection vulnerability [CWE-89] in the album_id shortcode attribute. The flaw affects all versions up to and including 1.8.44. The plugin fails to properly escape user-supplied input and does not use prepared statements for the affected SQL query. Authenticated users with author-level access or above can append SQL payloads that extract sensitive data from the WordPress database. The unsanitized value appears on both sides of a UNION query, which can double the observable time-based delay during exploitation.
Critical Impact
An author-level user can embed a SQL injection payload inside a shortcode attribute in a published post. The payload executes whenever any visitor renders that post, exposing database contents such as password hashes and session tokens.
Affected Products
- Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress, all versions up to and including 1.8.44
- Affected component: frontend/models/model.php (lines 172 and 178)
- Affected component: frontend/controllers/controller.php and framework/WDWLibrary.php
Discovery Timeline
- 2026-09-18 - CVE-2026-85652 published to the National Vulnerability Database (NVD)
- 2026-09-18 - Last updated in NVD database
Technical Details for CVE-2026-85652
Vulnerability Analysis
The vulnerability resides in the frontend rendering path of the Photo Gallery plugin. When a post containing the plugin's shortcode is rendered, the album_id attribute is passed into a SQL query without adequate escaping or parameterization. The query construction relies on string concatenation rather than the $wpdb->prepare() API, which allows attacker-controlled input to break out of the intended value context.
Because the injected value is referenced on both sides of a UNION query, a time-based payload using functions such as SLEEP() runs twice per request. This amplification makes blind extraction faster and more reliable for the attacker. Successful exploitation permits enumeration of arbitrary database contents, including WordPress user credentials and secrets stored in wp_options.
See the Wordfence Vulnerability Report and the WordPress Photo Gallery Changeset Summary for the vendor fix.
Root Cause
The root cause is insufficient input sanitization and the absence of prepared statements in the query built from the album_id shortcode attribute. The framework helper in framework/WDWLibrary.php does not enforce integer casting on the parameter before it reaches the model. Review the vulnerable code paths in WDWLibrary.php line 75, controller.php line 51, model.php line 172, and model.php line 178.
Attack Vector
An authenticated attacker with author-level privileges publishes a post containing the plugin's shortcode with a malicious album_id value. The injected SQL executes each time the post is rendered, meaning any unauthenticated visitor triggers the payload. The attack is remote and requires low complexity, with no user interaction beyond normal browsing of the compromised post.
No public proof-of-concept exploit code is available. Refer to the vendor references above for the vulnerable code paths.
Detection Methods for CVE-2026-85652
Indicators of Compromise
- New or modified posts authored by low-privilege accounts containing [wd_asp] or Photo Gallery shortcodes with unusual album_id values such as SQL keywords, UNION SELECT, SLEEP(, or hex-encoded strings
- Web server access log entries showing unusually long response times for pages hosting Photo Gallery shortcodes
- MySQL slow query log entries referencing the wp_wdpg_album or related plugin tables with unexpected UNION clauses
Detection Strategies
- Audit all published and draft posts for Photo Gallery shortcodes and inspect the album_id attribute for non-integer values
- Enable and review the MySQL general query log during triage to identify injected UNION or SLEEP payloads originating from plugin queries
- Correlate author-level user activity with post creation and edit events using WordPress audit plugins or webserver logs
Monitoring Recommendations
- Monitor page render latency for URLs that embed the plugin's shortcodes, alerting on statistically abnormal delays consistent with SLEEP() payloads
- Track privilege changes and new author-role account creation events in WordPress
- Forward WordPress, PHP-FPM, and database logs to a centralized analytics platform to detect anomalous query patterns
How to Mitigate CVE-2026-85652
Immediate Actions Required
- Update the Photo Gallery by 10Web plugin to a version later than 1.8.44 as soon as the patched release is available from the WordPress plugin repository
- Audit accounts holding the Author role or higher and remove any that are not required for site operations
- Review recent posts and pages for Photo Gallery shortcodes containing suspicious album_id attribute values and unpublish or sanitize them
- Rotate WordPress user passwords and any secrets stored in wp_options if evidence of exploitation exists
Patch Information
The vendor addressed the issue in the changeset referenced by the WordPress Photo Gallery Changeset Summary. Site administrators should apply the fixed release published on the plugin's page after 1.8.44. Consult the Wordfence Vulnerability Report for the confirmed fixed version and remediation guidance.
Workarounds
- Restrict the Author role to trusted users only and require multi-factor authentication for all contributors
- Deploy a web application firewall (WAF) rule that blocks shortcode requests containing SQL keywords such as UNION, SLEEP, BENCHMARK, or SELECT in the album_id parameter
- Temporarily deactivate the Photo Gallery plugin on sites that cannot immediately upgrade
# Example WP-CLI commands to inventory and mitigate exposure
wp plugin get photo-gallery --field=version
wp post list --post_status=publish,draft --s='[wd_asp' --format=csv
wp plugin deactivate photo-gallery
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
