The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-01T21:18:06.390Z

Reserved: 2024-05-31T18:22:56.272Z

Link: CVE-2024-5570

cve-icon Vulnrichment

Updated: 2024-08-01T21:18:06.390Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-28T06:15:06.593

Modified: 2024-11-21T09:47:56.960

Link: CVE-2024-5570

cve-icon Redhat

No data.