CVE · Medium

CVE-2024-8431 — Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8431 Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22 Missing Authorization Medium 4.3 < 3.2.22 3.2.22 2024-10-07

CVE-2024-8431

A flaw exists in Rbs Image Gallery plugin's AJAX handling mechanism, specifically within the ajaxGetGalleryJson() function, where a capability check is absent, allowing authorized users with elevated permissions or higher to bypass intended data restrictions. This oversight enables such individuals to access and view private post title information without proper authorization. The vulnerability affects all versions of the plugin up to and including 3.2.21.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.