CVE · Medium

CVE-2022-45804 — Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-45804 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.11 Cross-Site Request Forgery (CSRF) Medium 5.4 < 3.2.11 3.2.11 2023-02-02

CVE-2022-45804

The Robo Gallery plugin before version 3.2.11 contains a cross-site request forgery vulnerability that could enable an attacker to trick authenticated users with elevated privileges into performing unintended actions. This flaw could be exploited to change administrative passwords, granting the attacker unauthorized access to the admin account. The vulnerability was discovered by Lana Codes and has been resolved in version 3.2.11 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.