The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to expose private, pending, trashed, and draft post titles. Successful exploitation requires the Elementor plugin to be installed and activated.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Oct 2024 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codesupply
Codesupply sight |
|
CPEs | cpe:2.3:a:codesupply:sight:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Codesupply
Codesupply sight |
Thu, 26 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codesupplyco
Codesupplyco sight Professional Image Gallery And Portfolio |
|
CPEs | cpe:2.3:a:codesupplyco:sight_professional_image_gallery_and_portfolio:*:*:*:*:*:*:*:* | |
Vendors & Products |
Codesupplyco
Codesupplyco sight Professional Image Gallery And Portfolio |
|
Metrics |
ssvc
|
Thu, 26 Sep 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to expose private, pending, trashed, and draft post titles. Successful exploitation requires the Elementor plugin to be installed and activated. | |
Title | Sight – Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-26T08:29:46.489Z
Updated: 2024-09-26T13:36:19.248Z
Reserved: 2024-09-19T23:14:31.541Z
Link: CVE-2024-9025
Vulnrichment
Updated: 2024-09-26T13:36:12.318Z
NVD
Status : Analyzed
Published: 2024-09-26T09:15:03.970
Modified: 2024-10-01T13:44:23.667
Link: CVE-2024-9025
Redhat
No data.