The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them
History

Mon, 19 May 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Zitscher
Zitscher simple Photoswipe
Weaknesses CWE-862
CPEs cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:*
Vendors & Products Zitscher
Zitscher simple Photoswipe

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-06-28T06:00:03.518Z

Updated: 2024-08-01T21:18:06.390Z

Reserved: 2024-05-31T18:22:56.272Z

Link: CVE-2024-5570

cve-icon Vulnrichment

Updated: 2024-08-01T21:18:06.390Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-28T06:15:06.593

Modified: 2025-05-19T20:46:21.440

Link: CVE-2024-5570

cve-icon Redhat

No data.