Contest Gallery - Broken Access Control
Contest Gallery from n/a through 23.1.2 contains an exposure of sensitive information to an unauthorized actor caused by insufficient access controls, letting attackers access sensitive data, exploit requires no specific conditions. References: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contest-gallery/contest-gallery-2312-unauthenticated-information-exposure https://nvd.nist.gov/vuln/detail/CVE-2024-43283 Remediation: Update to the latest version 23.1.2 or later to address the issue.
Used 2.8k times · 1 assets checked · domain, subdomain, ipv4