Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNews10Web WordPress Photo Gallery Plugin Vulnerability via @Sejournal, @Martinibuster
10Web WordPress Photo Gallery Plugin Vulnerability via @Sejournal, @Martinibuster
Digital MarketingCybersecurity

10Web WordPress Photo Gallery Plugin Vulnerability via @Sejournal, @Martinibuster

•January 22, 2026
0
Search Engine Journal
Search Engine Journal•Jan 22, 2026

Companies Mentioned

Shutterstock

Shutterstock

SSTK

Why It Matters

Unauthenticated comment deletion can erode trust and damage engagement on visual‑content sites, making rapid patching essential for WordPress administrators.

Key Takeaways

  • •Unauthenticated users can delete image comments
  • •Affects Photo Gallery by 10Web up to v1.8.36
  • •Issue resides in missing capability check
  • •Patch released in version 1.8.37
  • •Disable comments or plugin as temporary mitigation

Pulse Analysis

The Photo Gallery by 10Web plugin powers thousands of WordPress sites that showcase portfolios, product catalogs, and photography collections. Its widespread adoption makes any security flaw a high‑visibility risk, especially when the vulnerability bypasses WordPress's built‑in permission framework. Missing capability checks are a classic oversight that lets anyone invoke privileged functions, highlighting the need for rigorous code reviews and automated testing in the plugin development lifecycle.

While the vulnerability does not grant full site takeover, the ability to delete image comments can undermine community interaction and erase valuable feedback. For businesses that rely on visual storytelling, comments often serve as social proof and a channel for customer insights. Their sudden removal can distort analytics, diminish user trust, and potentially affect SEO rankings if comment‑derived content disappears. Even a medium‑severity rating warrants swift action because the exploit requires no authentication, lowering the barrier for opportunistic attackers.

The good news is that the developer released a fix in version 1.8.37, underscoring the importance of maintaining up‑to‑date plugins. Site owners should prioritize this update, test it in staging environments, and consider disabling the comments feature if immediate patching isn’t feasible. This incident also serves as a reminder for the broader WordPress ecosystem: regular vulnerability scanning, employing security plugins like Wordfence, and enforcing a disciplined patch management process are essential defenses against similar threats.

10Web WordPress Photo Gallery Plugin Vulnerability via @sejournal, @martinibuster

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...