PT-2024-30448 · WordPress · Contest Gallery
Joshua Chan
·
Published
2024-08-26
·
Updated
2026-01-30
·
CVE-2024-43283
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Contest Gallery versions prior to 23.1.3
Description
The issue is related to the exposure of sensitive information to an unauthorized actor. This affects the Contest Gallery plugin for WordPress, potentially disclosing unauthorized comment user ID and IP address. Users are urged to upgrade to mitigate the risk.
Recommendations
For versions prior to 23.1.3, upgrade to version 23.1.3 to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Contest Gallery