PT-2024-15072 · WordPress · Envira Photo Gallery
Nex Team
+1
·
Published
2024-01-11
·
Updated
2024-01-17
·
CVE-2023-6742
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Envira Photo Gallery plugin for WordPress versions up to, and including, 1.8.7.1
Description
The issue allows authenticated attackers with contributor access and above to modify galleries on other users' posts due to an improper capability check on the
envira gallery insert images function.Recommendations
For versions up to, and including, 1.8.7.1, update to a version higher than 1.8.7.1 to resolve the issue. As a temporary workaround, consider restricting access to the
envira gallery insert images function to prevent unauthorized modifications.Fix
Missing Authorization
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Envira Photo Gallery