Skip to main content
Vulnerability Database/CVE-2026-85652

CVE-2026-85652: Photo Gallery by 10Web SQL Injection Flaw

CVE-2026-85652 is a time-based SQL injection vulnerability in the Photo Gallery by 10Web WordPress plugin that allows authenticated attackers to extract sensitive database information. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2026-85652 Overview

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress contains a time-based SQL Injection vulnerability [CWE-89] in the album_id shortcode attribute. The flaw affects all versions up to and including 1.8.44. The plugin fails to properly escape user-supplied input and does not use prepared statements for the affected SQL query. Authenticated users with author-level access or above can append SQL payloads that extract sensitive data from the WordPress database. The unsanitized value appears on both sides of a UNION query, which can double the observable time-based delay during exploitation.

Critical Impact

An author-level user can embed a SQL injection payload inside a shortcode attribute in a published post. The payload executes whenever any visitor renders that post, exposing database contents such as password hashes and session tokens.

Affected Products

  • Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress, all versions up to and including 1.8.44
  • Affected component: frontend/models/model.php (lines 172 and 178)
  • Affected component: frontend/controllers/controller.php and framework/WDWLibrary.php

Discovery Timeline

  • 2026-09-18 - CVE-2026-85652 published to the National Vulnerability Database (NVD)
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-85652

Vulnerability Analysis

The vulnerability resides in the frontend rendering path of the Photo Gallery plugin. When a post containing the plugin's shortcode is rendered, the album_id attribute is passed into a SQL query without adequate escaping or parameterization. The query construction relies on string concatenation rather than the $wpdb->prepare() API, which allows attacker-controlled input to break out of the intended value context.

Because the injected value is referenced on both sides of a UNION query, a time-based payload using functions such as SLEEP() runs twice per request. This amplification makes blind extraction faster and more reliable for the attacker. Successful exploitation permits enumeration of arbitrary database contents, including WordPress user credentials and secrets stored in wp_options.

See the Wordfence Vulnerability Report and the WordPress Photo Gallery Changeset Summary for the vendor fix.

Root Cause

The root cause is insufficient input sanitization and the absence of prepared statements in the query built from the album_id shortcode attribute. The framework helper in framework/WDWLibrary.php does not enforce integer casting on the parameter before it reaches the model. Review the vulnerable code paths in WDWLibrary.php line 75, controller.php line 51, model.php line 172, and model.php line 178.

Attack Vector

An authenticated attacker with author-level privileges publishes a post containing the plugin's shortcode with a malicious album_id value. The injected SQL executes each time the post is rendered, meaning any unauthenticated visitor triggers the payload. The attack is remote and requires low complexity, with no user interaction beyond normal browsing of the compromised post.

No public proof-of-concept exploit code is available. Refer to the vendor references above for the vulnerable code paths.

Detection Methods for CVE-2026-85652

Indicators of Compromise

  • New or modified posts authored by low-privilege accounts containing [wd_asp] or Photo Gallery shortcodes with unusual album_id values such as SQL keywords, UNION SELECT, SLEEP(, or hex-encoded strings
  • Web server access log entries showing unusually long response times for pages hosting Photo Gallery shortcodes
  • MySQL slow query log entries referencing the wp_wdpg_album or related plugin tables with unexpected UNION clauses

Detection Strategies

  • Audit all published and draft posts for Photo Gallery shortcodes and inspect the album_id attribute for non-integer values
  • Enable and review the MySQL general query log during triage to identify injected UNION or SLEEP payloads originating from plugin queries
  • Correlate author-level user activity with post creation and edit events using WordPress audit plugins or webserver logs

Monitoring Recommendations

  • Monitor page render latency for URLs that embed the plugin's shortcodes, alerting on statistically abnormal delays consistent with SLEEP() payloads
  • Track privilege changes and new author-role account creation events in WordPress
  • Forward WordPress, PHP-FPM, and database logs to a centralized analytics platform to detect anomalous query patterns

How to Mitigate CVE-2026-85652

Immediate Actions Required

  • Update the Photo Gallery by 10Web plugin to a version later than 1.8.44 as soon as the patched release is available from the WordPress plugin repository
  • Audit accounts holding the Author role or higher and remove any that are not required for site operations
  • Review recent posts and pages for Photo Gallery shortcodes containing suspicious album_id attribute values and unpublish or sanitize them
  • Rotate WordPress user passwords and any secrets stored in wp_options if evidence of exploitation exists

Patch Information

The vendor addressed the issue in the changeset referenced by the WordPress Photo Gallery Changeset Summary. Site administrators should apply the fixed release published on the plugin's page after 1.8.44. Consult the Wordfence Vulnerability Report for the confirmed fixed version and remediation guidance.

Workarounds

  • Restrict the Author role to trusted users only and require multi-factor authentication for all contributors
  • Deploy a web application firewall (WAF) rule that blocks shortcode requests containing SQL keywords such as UNION, SLEEP, BENCHMARK, or SELECT in the album_id parameter
  • Temporarily deactivate the Photo Gallery plugin on sites that cannot immediately upgrade
bash
# Example WP-CLI commands to inventory and mitigate exposure
wp plugin get photo-gallery --field=version
wp post list --post_status=publish,draft --s='[wd_asp' --format=csv
wp plugin deactivate photo-gallery

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.