The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post.
References
Configurations
History
No history.
Information
Published : 2023-07-12 05:15
Updated : 2023-11-07 04:12
NVD link : CVE-2023-2562
Mitre link : CVE-2023-2562
CVE.ORG link : CVE-2023-2562
JSON object : View
Products Affected
gallery-metabox_project
- gallery-metabox
CWE
CWE-862
Missing Authorization