CVE-2024-12114: FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.29 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Post/Page Updates
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogalleryattachmentmodalsave AJAX action due to missing validation on a user controlled key (imgid). This makes it possible for authenticated attackers, with granted access and above, to update arbitrary post and page content. This requires the Gallery Creator Role setting to be a value lower than 'Editor' for there to be any real impact.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12114?
CVE-2024-12114 is classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2024-12114?
To fix CVE-2024-12114, upgrade the FooGallery plugin to version 2.4.30 or later which includes validation improvements.
What versions of FooGallery are affected by CVE-2024-12114?
CVE-2024-12114 affects all versions of FooGallery up to and including 2.4.29.
What type of vulnerability is CVE-2024-12114?
CVE-2024-12114 is an Insecure Direct Object Reference vulnerability.
Can CVE-2024-12114 lead to data exposure?
Yes, CVE-2024-12114 can lead to unauthorized access and potential exposure of sensitive user data.