ZeroHour

CVE-2024-5570

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p44
Published
()
Modified
Description

The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them

Vendors
zitscher
Products
simple photoswipe
Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.