CVE-2024-35628: WordPress Photo Gallery by 10Web plugin <= 1.8.25 - Broken Access Control vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.25.
Affected Software
3 affected components
10web Photo Gallery<=1.8.25
10web WordPress Photo Gallery<=1.8.25
10web Photo Gallery Wordpress<1.8.26
Remediation
Information
Update to 1.8.26 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·02:29 PM
Data Sourced
via MITRE·02:29 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35628?
CVE-2024-35628 is classified as a missing authorization vulnerability, potentially allowing unauthorized access.
2
How do I fix CVE-2024-35628?
To mitigate CVE-2024-35628, update the Photo Gallery by 10Web plugin to at least version 1.8.26.
3
Which versions are affected by CVE-2024-35628?
CVE-2024-35628 affects Photo Gallery by 10Web versions up to and including 1.8.25.
4
What are the potential impacts of CVE-2024-35628?
CVE-2024-35628 could allow malicious users to gain access to restricted areas of the Photo Gallery.
5
Who should be concerned about CVE-2024-35628?
Users of 10Web Photo Gallery and WordPress Photo Gallery versions up to 1.8.25 should be concerned about CVE-2024-35628.