CVE-2024-5570

The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them
Configurations

Configuration 1 (hide)

cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:*

History

19 May 2025, 20:46

Type Values Removed Values Added
First Time Zitscher simple Photoswipe
Zitscher
CWE CWE-862
References () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - () https://wpscan.com/vulnerability/49b3a8cb-f606-4cf7-80ec-bfdafd74e848/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:*

Information

Published : 2024-06-28 06:15

Updated : 2025-05-19 20:46


NVD link : CVE-2024-5570

Mitre link : CVE-2024-5570

CVE.ORG link : CVE-2024-5570


JSON object : View

Products Affected

zitscher

  • simple_photoswipe
CWE
CWE-862

Missing Authorization