The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2023-03-27T15:37:16.230Z
Updated: 2025-02-19T16:56:02.620Z
Reserved: 2023-01-23T13:24:15.816Z
Link: CVE-2023-0441

Updated: 2024-08-02T05:10:56.333Z

Status : Modified
Published: 2023-03-27T16:15:08.193
Modified: 2025-02-19T17:15:11.770
Link: CVE-2023-0441

No data.