Unauthorized Data Modification in ACF Photo Gallery Field Plugin for WordPress
CVE-2023-3957
4.3MEDIUM
Summary
The ACF Photo Gallery Field plugin for WordPress suffers from a security flaw that allows authenticated users with subscriber-level permissions or higher to exploit insufficient restrictions within the 'apg_profile_update' function. This vulnerability permits attackers to arbitrarily alter user meta values, which can potentially lead to unauthorized access or alterations of sensitive data, undermining the integrity of the site.
Affected Version(s)
ACF Photo Gallery Field * <= 1.9
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lana Codes