CVE-2024-3097
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.
El complemento WordPress Gallery Plugin – NextGEN Gallery para WordPress es vulnerable al acceso no autorizado a los datos debido a una falta de verificación de capacidad en la función get_item en versiones hasta la 3.59 incluida. Esto hace posible que atacantes no autenticados extraigan datos confidenciales, incluidos EXIF y otros metadatos de cualquier imagen cargada a través del complemento.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-03-29 CVE Reserved
- 2024-04-05 CVE Published
- 2024-04-26 First Exploit
- 2024-08-01 CVE Updated
- 2024-11-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (5)
URL | Date | SRC |
---|---|---|
https://github.com/Athos-Zago/CVE-2024-30973 | 2024-04-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Imagely Search vendor "Imagely" | Nextgen Gallery Search vendor "Imagely" for product "Nextgen Gallery" | < 3.59.1 Search vendor "Imagely" for product "Nextgen Gallery" and version " < 3.59.1" | wordpress |
Affected
|