CVE-2024-8431: Photo Gallery, Images, Slider in Rbs Image Gallery <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8431?
CVE-2024-8431 has a medium severity due to the potential for unauthorized data access.
How do I fix CVE-2024-8431?
To fix CVE-2024-8431, update the Rbs Image Gallery plugin to version 3.2.22 or later.
Who is affected by CVE-2024-8431?
CVE-2024-8431 affects all users of the Rbs Image Gallery plugin for WordPress versions up to and including 3.2.21.
What kind of vulnerability is CVE-2024-8431?
CVE-2024-8431 is an access control vulnerability that allows unauthorized access to gallery data.
What function is exploited in CVE-2024-8431?
CVE-2024-8431 exploits the ajaxGetGalleryJson() function due to a missing capability check.