/Vulnerability Library

Contest Gallery - Broken Access Control

CVE-2024-43283
Verified

Description

Contest Gallery from n/a through 23.1.2 contains an exposure of sensitive information to an unauthorized actor caused by insufficient access controls, letting attackers access sensitive data, exploit requires no specific conditions.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Published Date

November 30, 2025

Template Author

popcorn94

CVE-2024-43283.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2024-43283
CWE ID:
cwe-200

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/contest-gallery/contest-gallery-2312-unauthenticated-information-exposurehttps://nvd.nist.gov/vuln/detail/CVE-2024-43283

Remediation Steps

Update to the latest version 23.1.2 or later to address the issue.