What the vulnerability does
01Description
Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
Explanation of Vulnerability in Simple Terms
The Responsive Image Gallery and Gallery Album plugin for WordPress fails to properly check user permissions before allowing modifications to gallery settings and content. A logged-in user with low privileges can alter or delete galleries they should not have access to. The vulnerability affects versions up to 2.0.3.
What an attacker can do
A low-privilege user can modify or delete galleries belonging to other users.
Potential impact on your site
Galleries can be altered or deleted by users who should not have that access, risking data loss and site disruption.
Conditions required to exploit
Attacker must have a WordPress user account with at least low-level permissions.
Key dates
External resources
Related vulnerabilities