CVE-2024-13833
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-13833 refers to a vulnerability in the Album Gallery WordPress plugin, affecting versions up to 1.6.3. This issue permits authenticated attackers with Editor-level access or higher to inject PHP Objects via deserialization of untrusted gallery meta data. However, the vulnerability itself does not allow for code execution or file deletion without an additional plugin or theme containing a POP (Return-Oriented Programming) chain present. If exploited in conjunction with a POP chain, the attacker could potentially perform actions such as file deletion, data retrieval, or code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.