1 results (0.002 seconds)
CVSS: 5.4EPSS: %CPEs: 1EXPL: 0
CVE-2022-43471 – WP Bootstrap Gallery <= 1.1 - Missing Authorization
https://notcve.org/view.php?id=CVE-2022-43471
The WP Bootstrap Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_get_wpbgallery_update_imagetitle function in versions up to, and including, 1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update titles of arbitrary posts. • CWE-862: Missing Authorization •