CVE-2023-49774: WordPress WP Photo Album Plus plugin <= 8.5.02.005 - IP Bypass vulnerability
Published Jun 4, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
Affected Software
2 affected components
J.N. Breetvelt WP Photo Album Plus>=n/a, <=8.5.02.005
WordPress WP Photo Album Plus<=8.5.02.005
Remediation
Information
Update to 8.6.01.005 or a higher version.
Event History
Jun 4, 2024
CVE Published
via MITRE·11:23 AM
Data Sourced
via MITRE·11:23 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-49774?
CVE-2023-49774 is classified as a vulnerability that allows unauthorized access to sensitive information.
2
How do I fix CVE-2023-49774?
To fix CVE-2023-49774, update WP Photo Album Plus to version 8.5.02.006 or later.
3
Who is affected by CVE-2023-49774?
CVE-2023-49774 affects users of WP Photo Album Plus versions from n/a through 8.5.02.005.
4
What kind of data can be exposed due to CVE-2023-49774?
CVE-2023-49774 can expose sensitive information due to improper access control.
5
Is there a workaround for CVE-2023-49774?
There are no known effective workarounds for CVE-2023-49774; applying the latest update is recommended.