What the vulnerability does
01Description
Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Exporter: from n/a through 1.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Exporter: from n/a through 1.3.
Explanation of Vulnerability in Simple Terms
WordPress Gallery Exporter plugin versions up to 1.3 lack proper authorization checks, allowing authenticated users to read sensitive data they should not access. An attacker with a low-privilege account can retrieve confidential information from the plugin without additional interaction. Site administrators should update to a version newer than 1.3 as soon as possible.
What an attacker can do
Read sensitive data from the plugin that should be restricted to higher-privilege users.
Potential impact on your site
Any WordPress user account can access confidential plugin data, risking exposure of site configuration or user information.
Conditions required to exploit
Attacker must have a valid WordPress user account with at least low-level privileges.
Key dates
External resources
Related vulnerabilities