Report
The WP Bootstrap Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_get_wpbgallery_update_imagetitle function in versions up to, and including, 1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update titles of arbitrary posts.
Score:4.3
Severity:Medium
Version: 1.1
The plugin vendor has not patched this vulnerability at the moment.