Cross-Site Request Forgery Vulnerability in Tiefpunkt Add Linked Images To Gallery
CVE-2025-27277
7.1HIGH
Key Information:
- Vendor
- Tiefpunkt
- Status
- Add Linked Images To Gallery
- Vendor
- CVE Published:
- 24 February 2025
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Tiefpunkt Add Linked Images To Gallery plugin for WordPress, which allows unauthorized actions to be performed by attackers on behalf of users without their consent. This vulnerabilities poses a risk to users as it can lead to unauthorized access and compromise of user data. It affects versions of the plugin from n/a through 1.4, making it essential for users to be aware and update their installations to mitigate potential security risks.
Affected Version(s)
Add Linked Images To Gallery <= 1.4
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)