CVE-2024-12237

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 3, 2025
CWE ID 918

Summary

CVE-2024-12237 is a Server-Side Request Forgery (SSRF) vulnerability affecting the Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress. This issue, present in all versions up to 1.0.15, allows authenticated attackers with Subscriber-level access or higher to generate malicious requests through the rjg_get_youtube_info_justified_gallery_callback function. By doing so, they can make web requests to arbitrary locations from the affected application, potentially retrieving limited information from internal services. This vulnerability poses a significant risk to WordPress installations using the Photo Gallery Slideshow & Masonry Tiled Gallery plugin and should be addressed promptly by updating to the latest, patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share