What the vulnerability does
01Description
A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the file wp-media-cincopa.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. Upgrading to version 1.137 is able to address this issue. The name of the patch is ee28e91f4d5404905204c43b7b84a8ffecad932e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230264.
Explanation of Vulnerability in Simple Terms
02Summary
The Video Playlist and Gallery Plugin contains a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on behalf of an authenticated user. An attacker can craft a malicious link or page that, when visited by a logged-in site administrator, executes unwanted plugin operations without the user's knowledge or consent. This vulnerability requires user interaction and affects the plugin's integrity but not data confidentiality.
What an attacker can do
03Attacker Capabilities
Perform unauthorized plugin actions on behalf of a logged-in administrator who visits a malicious page.
Potential impact on your site
04Site Impact
An attacker can modify plugin settings or content through a logged-in admin's browser without their knowledge.
Conditions required to exploit
05Prerequisites
An authenticated site administrator must visit an attacker-controlled page or click a malicious link while logged in.
Key dates
06Disclosure timeline
June 1, 2023
CVE published
August 6, 2024
Record updated