### [CVE-2021-25041](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25041) ![](https://img.shields.io/static/v1?label=Product&message=Photo%20Gallery%20by%2010Web%20%E2%80%93%20Mobile-Friendly%20Image%20Gallery&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=1.5.68%3C%201.5.68%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen) ### Description The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action ### POC #### Reference - https://wpscan.com/vulnerability/32aee3ea-e0af-44da-a16c-102c83eaed8f #### Github No PoCs found on GitHub currently.