CVE-2024-4551
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Jun 15, 2024
Updated: Jun 17, 2024
Summary
CVE-2024-4551 is a local file inclusion vulnerability affecting the Video Gallery – YouTube Playlist and Channel Gallery plugin for WordPress. The issue lies within the display function in all versions up to 1.3.13. This flaw grants authenticated attackers, including contributors and higher, the ability to include and execute arbitrary PHP files on the server. Consequently, attackers can bypass access controls, obtain sensitive data, or execute code, posing a significant security risk, especially when "safe" file types can be uploaded and included.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Video Gallery Plugin