Unauthorized Data Access in Gallery Metabox for WordPress
CVE-2023-2562
4.3MEDIUM
What is CVE-2023-2562?
The Gallery Metabox for WordPress is susceptible to unauthorized access due to the absence of a capability check in the refresh_metabox function. This vulnerability allows attackers with subscriber-level permissions to retrieve a list of images linked to a post, potentially exposing sensitive data.
Affected Version(s)
Gallery Metabox * <= 1.5