What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
Explanation of Vulnerability in Simple Terms
WP Photo Album Plus versions up to 8.5.02.005 contain an integrity vulnerability that allows unauthenticated attackers to modify data over the network without user interaction. The vulnerability stems from insufficient input validation or access controls. Site administrators should update to a version newer than 8.5.02.005 to remediate the issue.
What an attacker can do
Modify site data without authentication or user interaction.
Potential impact on your site
Attackers can alter plugin data, potentially affecting photo albums, settings, or other stored information.
Conditions required to exploit
Network access only; no authentication or user action required.
Key dates
External resources
Related vulnerabilities