CVE-2024-5570

T

he Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them

Configurations

Configuration 1 (hide)

cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:*

History

19 May 2025, 20:46

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - Exploit, Third Party Advisory
CWE CWE-862
CPE cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:*
First Time Zitscher
Zitscher simple Photoswipe

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ -

09 Jul 2024, 16:23

Type Values Removed Values Added
Summary
  • (es) El complemento Simple Photoswipe de WordPress hasta la versión 0.1 no tiene verificación de autorización al actualizar su configuración, lo que podría permitir que cualquier usuario autenticado, como un suscriptor, los actualice.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

28 Jun 2024, 10:27

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 06:15

Updated : 2025-05-19 20:46


NVD link : CVE-2024-5570

Mitre link : CVE-2024-5570

CVE.ORG link : CVE-2024-5570


JSON object : View

Products Affected
CWE
CWE-862

Missing Authorization