PT-2021-15990 · WordPress · Meow Gallery

Apple502J

·

Published

2021-10-04

·

Updated

2021-10-08

·

CVE-2021-24465

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Meow Gallery WordPress plugin versions prior to 4.1.9
Description The issue arises from the Meow Gallery WordPress plugin's failure to sanitise, validate, or escape the ids attribute of its gallery shortcode, which is accessible to users with Contributor roles or higher. This oversight leads to an authenticated SQL Injection issue, allowing the manipulation of returned values. This manipulation can result in data disclosure and the deserialization of arbitrary objects.
Recommendations For versions prior to 4.1.9, update to version 4.1.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the gallery shortcode for users with Contributor roles or higher until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24465

Affected Products

Meow Gallery