What the vulnerability does
01Description
Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.
Explanation of Vulnerability in Simple Terms
The Video Gallery plugin for WordPress versions up to 1.3.4.5 contains an input validation flaw that allows attackers to inject malicious content into the site. An attacker must trick a site visitor into clicking a crafted link. The injected content can modify page behavior or redirect users, but cannot access sensitive data or take the site offline.
What an attacker can do
Inject malicious scripts or content into pages viewed by site visitors.
Potential impact on your site
Visitors may see altered page content, redirects, or malicious scripts; site data and availability are not directly compromised.
Conditions required to exploit
Site visitor must click an attacker-supplied link or visit a malicious page.
Key dates
External resources