Contest Gallery < 13.1.0.7 - Authenticated Email Address Disclosure
2021-11-01 00:00
WPScanTeamStrategic Overview
StatusPatched in 13.1.0.7
Affected Version
< 13.1.0.7CVSS4.3Medium
CVE
N/AVulnerability Overview
The Contest Gallery plugin for WordPress is vulnerable to Sensitive Data Exposure in versions before 13.1.0.7 via the cg_remove_not_required_coded_csvs function due to insufficient capability checks. This makes it possible for authenticated attackers with subscriber-level privileges and above to extract sensitive data including usernames and email addresses.
Technical Analysis
REMEDIATION: Update to version 13.1.0.7, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C