Lucene search

K
cveWordfenceCVE-2023-2561
HistoryJul 12, 2023 - 5:15 a.m.

CVE-2023-2561

2023-07-1205:15:09
Wordfence
web.nvd.nist.gov
13
cve-2023-2561
wordpress
gallery metabox
vulnerability
data modification
unauthorized access

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

40.7%

The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.

Affected configurations

Nvd
Vulners
Node
gallery-metabox_projectgallery-metaboxRange1.5wordpress
VendorProductVersionCPE
gallery-metabox_projectgallery-metabox*cpe:2.3:a:gallery-metabox_project:gallery-metabox:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "billerickson",
    "product": "Gallery Metabox",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "1.5",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

40.7%

Related for CVE-2023-2561