Missing Authorization vulnerability Affects Image Gallery
CVE-2024-35721
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 10 June 2024
Summary
A missing authorization vulnerability was identified in the Image Gallery – Lightbox Gallery, Responsive Photo Gallery, and Masonry Gallery plugins developed by WP Life. This vulnerability could allow unauthorized users to access restricted functionalities, potentially leading to manipulation or exposure of sensitive gallery content. The issue affects specific versions of the gallery plugins, making it crucial for users currently using versions up to 1.4.5 to take proactive measures to secure their installations against potential exploitation.
Affected Version(s)
Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery <= 1.4.5
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Steven Julian (Patchstack Alliance)