PT-2024-36578 · WordPress · Simple Photoswipe

·

CVE-2024-5570

·

Published

2024-06-28

·

Updated

2025-05-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Simple Photoswipe WordPress plugin version 0.1
Description The issue concerns a lack of authorization checks when updating settings, potentially allowing any authenticated user to modify them.
Recommendations For Simple Photoswipe WordPress plugin version 0.1, consider disabling the settings update functionality until a patch is available to prevent unauthorized changes.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5570

Affected Products

Simple Photoswipe