The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Oct 2024 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles. | |
Title | Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-08T11:34:18.616Z
Updated: 2024-10-08T13:50:56.799Z
Reserved: 2024-09-04T15:34:49.642Z
Link: CVE-2024-8431
Vulnrichment
Updated: 2024-10-08T12:45:07.010Z
NVD
Status : Awaiting Analysis
Published: 2024-10-08T12:15:02.810
Modified: 2024-10-10T12:56:30.817
Link: CVE-2024-8431
Redhat
No data.