Directory Traversal Vulnerability in Photo Gallery by 10Web for WordPress
CVE-2024-0221
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 5 February 2024
Summary
The Photo Gallery plugin by 10Web for WordPress contains a Directory Traversal vulnerability that affects all versions up to and including 1.8.19. Exploitation occurs via the rename_item function, granting authenticated attackers the ability to rename arbitrary files on the server. This serious flaw poses a risk of site takeovers, particularly if the critical wp-config.php file is targeted. Although primarily exploitable by administrators, the premium version of the plugin allows for gallery management permissions to be granted to lower-level users, potentially widening the attack surface to contributors and others with limited access privileges.
Affected Version(s)
Photo Gallery by 10Web – Mobile-Friendly Image Gallery * <= 1.8.19
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved