CVE-2024-5343: Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.19 - Cross-Site Request Forgery to Post Creation and Limited Data Loss
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbsajaxcreatearticle' and 'rbsajaxresetviews' functions. This makes it possible for unauthenticated attackers to create new posts and reset gallery view counts via a forged request granted they can trick a Contributor+ level user into performing an action such as clicking on a link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Rbs Image Gallery (Photo Gallery, Images, Slider)to a version that resolves this vulnerability.Fixed in 3.2.19 - Compensating control
Prevent CSRF exploitation by ensuring Contributor+ users do not follow untrusted links (e.g., limit access to untrusted content and use browser/workflow controls) so attackers cannot trick them into triggering forged requests that create posts or reset gallery view counts.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5343?
CVE-2024-5343 is classified as a moderate vulnerability due to its Cross-Site Request Forgery exposure.
How do I fix CVE-2024-5343?
To fix CVE-2024-5343, update the Rbs Image Gallery plugin to version 3.2.20 or later.
What versions of Rbs Image Gallery are affected by CVE-2024-5343?
CVE-2024-5343 affects all versions of the Rbs Image Gallery plugin up to and including 3.2.19.
What are the consequences of exploitation for CVE-2024-5343?
Exploitation of CVE-2024-5343 could allow an attacker to perform unauthorized actions on behalf of authenticated users.
Is there a patch available for CVE-2024-5343?
Yes, a patch was included in the Rbs Image Gallery plugin update to version 3.2.20.