What the vulnerability does
01Description
Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7.
Explanation of Vulnerability in Simple Terms
Responsive Lightbox through version 2.4.7 lacks proper authorization checks, allowing unauthenticated attackers to trigger a denial-of-service condition via network requests. The vulnerability does not require user interaction or special privileges. Site availability may be impacted if the plugin is actively exploited.
What an attacker can do
Make the site unavailable or unresponsive by sending repeated requests to the vulnerable component.
Potential impact on your site
Your site may become slow or temporarily unavailable if an attacker exploits this vulnerability.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities