The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles.
References
Configurations
No configuration.
History
10 Oct 2024, 12:56
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
08 Oct 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-08 12:15
Updated : 2024-10-10 12:56
NVD link : CVE-2024-8431
Mitre link : CVE-2024-8431
CVE.ORG link : CVE-2024-8431
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization