Description
The MaxGalleria plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability check on the add_media_library_images_to_gallery function in all versions up to, and including, 6.4.2. This makes it possible for authenticated attackers, with subscriber access or above, to upload arbitrary images to a gallery.
Problem types
Product status
* (semver)
Timeline
| 2024-04-19: | Disclosed |
Credits
Lucio Sá
References
www.wordfence.com/...-ede2-43ac-9ec4-2cd99cd34ae2?source=cve
plugins.trac.wordpress.org/.../maxgalleria-image-gallery.php
plugins.trac.wordpress.org/...%2Ftrunk&sfp_email=&sfph_mail=