CVE · Medium

CVE-2024-39640 — Social Feed Gallery [insta-gallery] < 4.4.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-39640 Social Feed Gallery [insta-gallery] < 4.4.0 Missing Authorization Medium 6.5 < 4.4.0 4.4.0 2024-08-01

CVE-2024-39640

The WP Social Feed Gallery plugin up through version 4.3.9 contains a flaw in the init_add_account() function that fails to verify user permissions, allowing unauthenticated attackers to establish account connections without proper authorization. This vulnerability enables unauthorized modification of plugin data through account linking functionality that should be restricted to privileged users. The issue was resolved in version 4.4.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.