PT-2022-4433 · WordPress · Yotuwp Video Gallery

Muhammad Daffa

·

Published

2022-08-23

·

Updated

2022-08-26

·

CVE-2022-35726

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions yotuwp Video Gallery plugin versions 1.3.4.5 and earlier
Description The issue is related to a Broken Authentication vulnerability in the yotuwp Video Gallery plugin for WordPress. This vulnerability is associated with weaknesses in the authentication procedure, which can be exploited by a remote attacker to bypass existing security restrictions.
Recommendations For yotuwp Video Gallery plugin versions 1.3.4.5 and earlier, update to a version later than 1.3.4.5 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's authentication functionality until a patch is available.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2022-05297
CVE-2022-35726

Affected Products

Yotuwp Video Gallery