CVE-2024-49258 MEDIUM

CVE-2024-49258: WordPress Limb Gallery plugin <= 1.5.7 - Arbitrary File Download vulnerability

Vendor Limbcode
Product WordPress Gallery Plugin – Limb Image Gallery
Weakness CWE-35
Published October 16, 2024
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through <= 1.5.7.

Explanation of Vulnerability in Simple Terms

02Summary

The Limb Image Gallery WordPress plugin through version 1.5.7 contains an information disclosure vulnerability. An authenticated user with low privileges can read sensitive data they should not have access to. The vulnerability requires a valid WordPress account but no additional user interaction. Site administrators should update the plugin immediately to prevent unauthorized data exposure.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the site that should be restricted to higher-privilege users.

Potential impact on your site

04Site Impact

Unauthorized users can access confidential information stored by the plugin, potentially including gallery metadata or configuration details.

Conditions required to exploit

05Prerequisites

Attacker must have a valid WordPress user account with low-level privileges (e.g., subscriber or contributor).

Key dates

06Disclosure timeline

October 16, 2024 CVE published
April 28, 2026 Record updated