The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ | Exploit Third Party Advisory |
Configurations
History
19 May 2025, 20:46
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-862 | |
References | () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - Exploit, Third Party Advisory | |
First Time |
Zitscher simple Photoswipe
Zitscher |
28 Jun 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-28 06:15
Updated : 2025-05-19 20:46
NVD link : CVE-2024-5570
Mitre link : CVE-2024-5570
JSON object : View
Products Affected
zitscher
- simple_photoswipe
CWE
CWE-862
Missing Authorization