WordPress Responsive Image Gallery, Gallery Album Plugin <= 2.0.3 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-45629

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
16 October 2023

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WPDevArt Gallery – Image and Video Gallery with Thumbnails plugin for WordPress versions 2.0.3 and earlier. This flaw could allow attackers to trick users into executing unintended actions on the affected site, which may lead to unauthorized modifications or data exposure. Site administrators are encouraged to update their installations to mitigate potential security risks associated with this vulnerability.

Affected Version(s)

Gallery – Image and Video Gallery with Thumbnails <= 2.0.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thiennv (Patchstack Alliance)
.