Impact
A Cross‑Site Request Forgery (CSRF) weakness exists in the Serhii Pasyuk Gmedia Photo Gallery WordPress plugin. The flaw permits an attacker to craft a request that performs an action on the target website using the credentials of a logged‑in user, thereby potentially altering data or executing unauthorized operations. The weakness is catalogued as CWE‑352, indicating that improper validation of request origin is the root cause.
Affected Systems
WordPress installations that have the Gmedia Photo Gallery plugin version 1.25.0 or earlier are impacted. The vendor is Serhii Pasyuk and the product is the Gmedia Photo Gallery plugin.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity, but the EPSS score of <1% suggests a very low probability of active exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, reflecting a lack of confirmed exploitation reports. The attack vector is inferred to be remote, requiring a victim to be authenticated and to visit a malicious site that submits a forged request to the vulnerable plugin's endpoints.
OpenCVE Enrichment