CVE-2024-33586: WordPress Photo Gallery by 10Web plugin <= 1.8.20 - Broken Access Control vulnerability
Published Apr 29, 2024
·Updated
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.
Affected Software
3 affected components
10web Photo Gallery<=1.8.20
10web WordPress Photo Gallery<=1.8.20
10web Photo Gallery Wordpress<1.8.21
Remediation
Information
Update to 1.8.21 or a higher version.
Event History
Apr 29, 2024
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33586?
CVE-2024-33586 has a moderate severity level due to its missing authorization issue.
2
How do I fix CVE-2024-33586?
To fix CVE-2024-33586, update Photo Gallery by 10Web to version 1.8.21 or later.
3
What software is affected by CVE-2024-33586?
CVE-2024-33586 affects Photo Gallery by 10Web versions up to and including 1.8.20.
4
What type of vulnerability is CVE-2024-33586?
CVE-2024-33586 is classified as a missing authorization vulnerability.
5
Can CVE-2024-33586 lead to unauthorized access?
Yes, CVE-2024-33586 can potentially allow unauthorized access due to inadequate authorization checks.