CVE Database /
CVE-2024-31252
CVE · High
CVE-2024-31252 — Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-31252
|
Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.7 |
Missing Authorization |
High
8.8
|
< 2.4.7
|
2.4.7 |
2024-04-05 |
—
|
CVE-2024-31252
The Responsive Lightbox & Gallery plugin for WordPress contains a broken access control flaw in versions before 2.4.7 that allows an unauthenticated or low-privilege user to perform actions normally restricted to higher-privilege accounts due to missing authorization checks and nonce verification. This vulnerability was identified by researcher emad and has been patched in version 2.4.7 and later. Users should update to version 2.4.7 or newer to mitigate the risk.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings