Description
The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization checks on the `vimeogallery_admin` function hooked to `admin_menu`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary plugin settings via the `action` parameter.
Problem types
Product status
* (semver)
Timeline
| 2025-12-11: | Disclosed |
Credits
Abhirup Konwar
References
www.wordfence.com/...-7023-481f-a05b-0b9a22d7a456?source=cve
plugins.trac.wordpress.org/.../trunk/vimeo_simplegallery.php
plugins.trac.wordpress.org/...gs/0.2/vimeo_simplegallery.php
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.