Cross-Site Request Forgery Vulnerability in WordPress Photo Gallery Plugin
CVE-2021-4384

4.3MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
1 July 2023

What is CVE-2021-4384?

The Photo Gallery – Image Gallery plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in specific functions. This flaw enables potential attackers to make unauthorized changes to galleries if they can manipulate a site administrator into executing malicious commands, such as clicking on a deceptive link. Users are urged to update to the latest version to mitigate this vulnerability.

Affected Version(s)

WordPress Photo Gallery – Image Gallery * <= 1.0.6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.