CVE-2024-11103: Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11103?
CVE-2024-11103 has been classified as a high severity vulnerability due to its potential for privilege escalation and account takeover.
How do I fix CVE-2024-11103?
To fix CVE-2024-11103, update the Contest Gallery plugin to version 24.0.8 or later, which addresses the identity validation issue.
Who is affected by CVE-2024-11103?
All versions of the Contest Gallery plugin for WordPress up to and including 24.0.7 are affected by CVE-2024-11103.
What does CVE-2024-11103 allow an attacker to do?
CVE-2024-11103 allows an attacker to potentially escalate their privileges by taking over an account due to insufficient identity validation.
Is there a workaround for CVE-2024-11103?
There is no official workaround for CVE-2024-11103; the only resolution is to update the plugin to a secure version.