ZeroHour

CVE-2023-6742

CVSS 3.1
4.3 medium
EPSS
<1%p34
Published
()
Modified
Description

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'envira_gallery_insert_images' function in all versions up to, and including, 1.8.7.1. This makes it possible for authenticated attackers, with contributor access and above, to modify galleries on other users' posts.

Vendors
enviragallery
Products
envira gallery
Ecosystems
WordPress
Weakness
CWE-862, CWE-754
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.