// For flags

CVE-2022-2224

Gallery for Social Photo <= 1.0.0.27 - Cross-Site Request Forgery to Post Duplication

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_duplicate_feed. This make it possible for unauthenticated attackers to duplicate existing posts or pages granted they can trick a site administrator into performing an action such as clicking on a link.

El plugin Gallery for Social Photo de WordPress es vulnerable a un ataque de tipo Cross-Site Request Forgery en versiones hasta 1.0.0.27 incluyéndola, debido a que no es comprobada apropiadamente la existencia de un nonce en la función gifeed_duplicate_feed. Esto hace posible que atacantes no autenticados dupliquen entradas o páginas existentes concedidas pueden engañar a un administrador del sitio para que lleve a cabo una acción como hacer clic en un enlace

*Credits: Marco Wotschka
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-24 CVE Published
  • 2022-06-27 CVE Reserved
  • 2024-02-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ghozylab
Search vendor "Ghozylab"
Gallery For Social Photo
Search vendor "Ghozylab" for product "Gallery For Social Photo"
<= 1.0.0.27
Search vendor "Ghozylab" for product "Gallery For Social Photo" and version " <= 1.0.0.27"
wordpress
Affected