CVE-2024-13833

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Mar 1, 2025
CWE ID 502

Summary

CVE-2024-13833 refers to a vulnerability in the Album Gallery WordPress plugin, affecting versions up to 1.6.3. This issue permits authenticated attackers with Editor-level access or higher to inject PHP Objects via deserialization of untrusted gallery meta data. However, the vulnerability itself does not allow for code execution or file deletion without an additional plugin or theme containing a POP (Return-Oriented Programming) chain present. If exploited in conjunction with a POP chain, the attacker could potentially perform actions such as file deletion, data retrieval, or code execution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share