CVE-2024-43924: WordPress Responsive Lightbox & Gallery plugin <= 2.4.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Responsive Lightbox: from n/a through 2.4.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43924?
CVE-2024-43924 has a high severity level due to the missing authorization which allows unauthorized access to certain functionalities.
How do I fix CVE-2024-43924?
To fix CVE-2024-43924, upgrade the dFactory Responsive Lightbox plugin to version 2.4.8 or later.
What impact does CVE-2024-43924 have on my WordPress site?
CVE-2024-43924 could allow attackers to access restricted functionalities, potentially compromising site security.
Which versions of Responsive Lightbox are affected by CVE-2024-43924?
CVE-2024-43924 affects dFactory Responsive Lightbox versions prior to 2.4.8, specifically up to 2.4.7.
Is there a workaround for CVE-2024-43924 if I cannot update immediately?
As a temporary workaround for CVE-2024-43924, consider disabling the plugin until you can upgrade to a secure version.