First published: Thu Jun 06 2024(Updated: )
The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Essentialplugin Album And Image Gallery Plus Lightbox | <2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4194 has a high severity rating due to the potential for arbitrary shortcode execution.
To fix CVE-2024-4194, update the Album and Image Gallery plus Lightbox plugin to version 2.1 or later.
CVE-2024-4194 affects all versions of the Album and Image Gallery plus Lightbox plugin up to and including version 2.0.
CVE-2024-4194 allows attackers to execute arbitrary shortcodes, potentially leading to unauthorized access or site compromise.
Yes, CVE-2024-4194 is specifically a vulnerability affecting the WordPress platform.