WordPress Robo Gallery Plugin <= 3.2.11 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-24414

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
20 May 2023

Summary

This vulnerability allows attackers to perform unauthorized actions on behalf of authenticated users through malicious requests. Users of the Rbs Image Gallery plugin versions 3.2.11 and earlier should take urgent action to mitigate the risks associated with this CSRF vulnerability. It is recommended to update the plugin to a secure version or implement protective measures to secure web applications against possible exploitation.

Affected Version(s)

Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.11

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thiennv (Patchstack Alliance)
.