What the vulnerability does
01Description
Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2.
Explanation of Vulnerability in Simple Terms
ThemeGoods Photography contains an authorization flaw that allows authenticated users with low privileges to read, modify, or disrupt site data they should not access. The vulnerability affects all versions up to 7.7.2. An attacker needs a valid user account to exploit it. Site owners should update to a version newer than 7.7.2 as soon as available.
What an attacker can do
Read, modify, or disrupt data without proper permission checks.
Potential impact on your site
Authenticated users can access or alter content and settings beyond their assigned role.
Conditions required to exploit
Attacker must have a valid user account on the site.
Key dates
External resources
Related vulnerabilities