CVE-2024-31342 MEDIUM

CVE-2024-31342: WordPress Gallery Exporter plugin <= 1.3 - Arbitrary File Download vulnerability

Vendor Wpcloudgallery
Product WordPress Gallery Exporter
Weakness CWE-862 · Missing authorization
Published April 10, 2024
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Exporter: from n/a through 1.3.

Explanation of Vulnerability in Simple Terms

02Summary

WordPress Gallery Exporter plugin versions up to 1.3 lack proper authorization checks, allowing authenticated users to read sensitive data they should not access. An attacker with a low-privilege account can retrieve confidential information from the plugin without additional interaction. Site administrators should update to a version newer than 1.3 as soon as possible.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the plugin that should be restricted to higher-privilege users.

Potential impact on your site

04Site Impact

Any WordPress user account can access confidential plugin data, risking exposure of site configuration or user information.

Conditions required to exploit

05Prerequisites

Attacker must have a valid WordPress user account with at least low-level privileges.

Key dates

06Disclosure timeline

April 10, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE