CVE-2024-3268
YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the emd_form_builder_lite_submit_form function in all versions up to, and including, 3.3.6. This makes it possible for unauthenticated attackers to create arbitrary posts or pages.
The YouTube Video Gallery by YouTube Showcase – Video Gallery complemento para WordPress es vulnerable a modificaciones no autorizadas de datos debido a una falta de verificación de capacidad en la función emd_form_builder_lite_submit_form en todas las versiones hasta la 3.3.6 incluida. Esto hace posible que atacantes no autenticados creen publicaciones o páginas arbitrarias.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-04-03 CVE Reserved
- 2024-05-20 CVE Published
- 2024-05-22 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://plugins.trac.wordpress.org/changeset/3088363/youtube-showcase | ||
https://www.wordfence.com/threat-intel/vulnerabilities/id/0e9d5382-d37d-4a40-8f22-e32b8ee98859?source=cve |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emarket-design Search vendor "Emarket-design" | YouTube Video Gallery Search vendor "Emarket-design" for product "YouTube Video Gallery" | <= 3.3.6 Search vendor "Emarket-design" for product "YouTube Video Gallery" and version " <= 3.3.6" | en |
Affected
|