WordPress Portfolio Gallery – Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control vulnerability
CVE-2023-32585
7.5HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 13 December 2024
Summary
A missing authorization vulnerability exists in Total-Soft's Portfolio Gallery – Responsive Image Gallery that allows attackers to exploit improperly configured access control mechanisms. This flaw can lead to unauthorized users gaining access to restricted content or functionalities within the gallery. The issue notably affects versions prior to 1.4.6, emphasizing the importance of applying appropriate access control measures and regularly updating plugins to mitigate potential security risks.
Affected Version(s)
Portfolio Gallery – Responsive Image Gallery <= 1.4.6
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
István Márton (Patchstack Alliance)