The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.
References
Configurations
History
No history.
Information
Published : 2023-07-12 05:15
Updated : 2023-11-07 04:12
NVD link : CVE-2023-2561
Mitre link : CVE-2023-2561
CVE.ORG link : CVE-2023-2561
JSON object : View
Products Affected
gallery-metabox_project
- gallery-metabox
CWE
No CWE.