What the vulnerability does
01Description
Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in dFactory Responsive Lightbox.This issue affects Responsive Lightbox: from n/a through 2.4.6.
Explanation of Vulnerability in Simple Terms
Responsive Lightbox through version 2.4.6 fails to properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read sensitive information they should not have access to. The vulnerability requires authentication but does not require user interaction to exploit.
What an attacker can do
Read sensitive information that should be restricted to higher-privilege users.
Potential impact on your site
Unauthorized users can access private or restricted data through the plugin, potentially exposing confidential information.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities