CVE-2024-5570

The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them
Configurations

Configuration 1 (hide)

cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:*

History

19 May 2025, 20:46

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - Exploit, Third Party Advisory
First Time Zitscher
Zitscher simple Photoswipe
CWE CWE-862
CPE cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:*

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ -

09 Jul 2024, 16:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
Summary
  • (es) El complemento Simple Photoswipe de WordPress hasta la versión 0.1 no tiene verificación de autorización al actualizar su configuración, lo que podría permitir que cualquier usuario autenticado, como un suscriptor, los actualice.

28 Jun 2024, 10:27

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-28 06:15

Updated : 2025-05-19 20:46


NVD link : CVE-2024-5570

Mitre link : CVE-2024-5570

CVE.ORG link : CVE-2024-5570


JSON object : View

Products Affected

zitscher

  • simple_photoswipe
CWE
CWE-862

Missing Authorization