PT-2024-31670 · Yotuwp · The Video Gallery – Youtube Playlist
Foxyyy
+1
·
Published
2024-06-15
·
Updated
2024-09-20
·
CVE-2024-4551
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress versions up to, and including, 1.3.13
Description:
The issue allows authenticated attackers with contributor access or higher to include and execute arbitrary PHP files on the server via the display function. This enables the execution of any PHP code in those files, potentially bypassing access controls, obtaining sensitive data, or achieving code execution, especially in scenarios where images and other "safe" file types can be uploaded and included.
Recommendations:
For versions up to, and including, 1.3.13, update to a version higher than 1.3.13 to resolve the issue. As a temporary workaround, consider restricting access to the display function to minimize the risk of exploitation. Additionally, restrict the ability to upload and include PHP files to prevent code execution.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Video Gallery – Youtube Playlist