Beta

Report

WP Bootstrap Gallery <= 1.1 is vulnerable to Broken Access Control vulnerability

Subscriber
Published
2022-10-27

The WP Bootstrap Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_get_wpbgallery_update_imagetitle function in versions up to, and including, 1.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update titles of arbitrary posts.

CVSS

Score:4.3

Severity:Medium

Version: 1.1

The plugin vendor has not patched this vulnerability at the moment.