WordPress Plugin Vulnerabilities

Album Gallery – WordPress Gallery < 1.5.0 - Cross-Site Request Forgery

Description

The plugin does not have CSRF checks (either flawed or missing completely) in when performing update actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

Affects Plugins

Fixed in 1.5.0

References

Classification

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2023-07-17 (about 2 years ago)
Added
2023-07-17 (about 2 years ago)
Last Updated
2023-07-17 (about 2 years ago)

Other