CVE-2023-33995: WordPress Photo Gallery by 10Web plugin <= 1.8.15 - Broken Access Control vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.15.
Affected Software
3 affected components
10web Photo Gallery<=1.8.15
10web Photo Gallery by 10Web<=1.8.15
10web Photo Gallery Wordpress<1.8.16
Remediation
Information
Update the WordPress Photo Gallery by 10Web plugin to the latest available version (at least 1.8.16).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-33995?
CVE-2023-33995 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-33995?
To fix CVE-2023-33995, update Photo Gallery by 10Web to version 1.8.16 or later.
3
What type of vulnerability is CVE-2023-33995?
CVE-2023-33995 is a Missing Authorization vulnerability resulting from incorrectly configured access control settings.
4
Which versions of Photo Gallery by 10Web are affected by CVE-2023-33995?
CVE-2023-33995 affects all versions of Photo Gallery by 10Web up to and including 1.8.15.
5
What could be the impact of exploiting CVE-2023-33995?
Exploitation of CVE-2023-33995 could allow unauthorized access to sensitive data or features within the Photo Gallery plugin.