Missing Authorization Vulnerability in 10Web's Photo Gallery Plugin
CVE-2024-33586

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 April 2024

What is CVE-2024-33586?

A missing authorization vulnerability exists within the Photo Gallery by 10Web, which could allow unauthorized access to sensitive data and functionalities. The issue affects versions from an unspecified version through 1.8.20. Attackers could exploit this flaw to manipulate user privileges and gain access to actions that should have been restricted, posing a significant risk to the integrity and confidentiality of user data within the application.

Affected Version(s)

Photo Gallery by 10Web <= 1.8.20

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.