CVE Database /
CVE-2024-39640
CVE · Medium
CVE-2024-39640 — Social Feed Gallery [insta-gallery] < 4.4.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-39640
|
Social Feed Gallery [insta-gallery] < 4.4.0 |
Missing Authorization |
Medium
6.5
|
< 4.4.0
|
4.4.0 |
2024-08-01 |
—
|
CVE-2024-39640
The WP Social Feed Gallery plugin up through version 4.3.9 contains a flaw in the init_add_account() function that fails to verify user permissions, allowing unauthenticated attackers to establish account connections without proper authorization. This vulnerability enables unauthorized modification of plugin data through account linking functionality that should be restricted to privileged users. The issue was resolved in version 4.4.0.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings