PT-2024-30448 · WordPress · Contest Gallery

Joshua Chan

·

Published

2024-08-26

·

Updated

2026-01-30

·

CVE-2024-43283

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Contest Gallery versions prior to 23.1.3
Description The issue is related to the exposure of sensitive information to an unauthorized actor. This affects the Contest Gallery plugin for WordPress, potentially disclosing unauthorized comment user ID and IP address. Users are urged to upgrade to mitigate the risk.
Recommendations For versions prior to 23.1.3, upgrade to version 23.1.3 to resolve the issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-43283

Affected Products

Contest Gallery