CVE · High

CVE-2024-31252 — Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-31252 Responsive Lightbox & Gallery [responsive-lightbox] < 2.4.7 Missing Authorization High 8.8 < 2.4.7 2.4.7 2024-04-05

CVE-2024-31252

The Responsive Lightbox & Gallery plugin for WordPress contains a broken access control flaw in versions before 2.4.7 that allows an unauthenticated or low-privilege user to perform actions normally restricted to higher-privilege accounts due to missing authorization checks and nonce verification. This vulnerability was identified by researcher emad and has been patched in version 2.4.7 and later. Users should update to version 2.4.7 or newer to mitigate the risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.