WordPress Portfolio Gallery – Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control vulnerability
CVE-2023-32585

7.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
13 December 2024

Summary

A missing authorization vulnerability exists in Total-Soft's Portfolio Gallery – Responsive Image Gallery that allows attackers to exploit improperly configured access control mechanisms. This flaw can lead to unauthorized users gaining access to restricted content or functionalities within the gallery. The issue notably affects versions prior to 1.4.6, emphasizing the importance of applying appropriate access control measures and regularly updating plugins to mitigate potential security risks.

Affected Version(s)

Portfolio Gallery – Responsive Image Gallery <= 1.4.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton (Patchstack Alliance)
.