The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them
Metrics
Affected Vendors & Products
References
History
Mon, 25 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tobias Cichon
Tobias Cichon simple Photoswipe |
|
| CPEs | cpe:2.3:a:tobias_cichon:simple_photoswipe:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tobias Cichon
Tobias Cichon simple Photoswipe |
|
| Metrics |
ssvc
|
Mon, 19 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zitscher
Zitscher simple Photoswipe |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:zitscher:simple_photoswipe:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Zitscher
Zitscher simple Photoswipe |
Status: PUBLISHED
Assigner: WPScan
Published: 2024-06-28T06:00:03.518Z
Updated: 2025-08-27T12:00:30.978Z
Reserved: 2024-05-31T18:22:56.272Z
Link: CVE-2024-5570
Updated: 2024-08-01T21:18:06.390Z
Status : Analyzed
Published: 2024-06-28T06:15:06.593
Modified: 2025-05-19T20:46:21.440
Link: CVE-2024-5570
No data.