CVE-2024-32778: WordPress Contest Gallery plugin <= 21.3.4 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 21.3.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32778?
CVE-2024-32778 has a medium severity rating due to its potential impact on user data and unauthorized access.
How do I fix CVE-2024-32778?
To fix CVE-2024-32778, update the Contest Gallery plugin to the latest version that addresses the authorization vulnerability.
Who is affected by CVE-2024-32778?
Users of Contest Gallery on WordPress versions up to and including 21.3.4 are affected by CVE-2024-32778.
What are the risks associated with CVE-2024-32778?
The risks include unauthorized access to sensitive data and potentially compromised user accounts due to missing authorization checks.
Is there a workaround for CVE-2024-32778?
A potential workaround is to restrict access to the Contest Gallery plugin until it can be updated to mitigate the vulnerability.