We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.
Reserved 2023-05-06 | Published 2023-07-12 | Updated 2024-10-22 | Assigner Wordfence2023-04-21: | Discovered |
2023-06-22: | Disclosed |
Marco Wotschka
www.wordfence.com/...-96d6-4937-a1f3-9d2d19bc6395?source=cve
plugins.trac.wordpress.org/...gallery-metabox.php?rev=611664
Support options