The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles.
We have discovered 7,820 live websites that are affected by CVE-2024-8431.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 7,820 live websites (48.52% of Robo Gallery install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 135 versions ( 96.43% of all versions) |
![]() | 2,316 websites |
![]() | 1,072 websites |
![]() | 490 websites |
![]() | 446 websites |
![]() | 315 websites |
![]() | 239 websites |
![]() | 229 websites |
![]() | 220 websites |
![]() | 173 websites |
![]() | 136 websites |
.com | 3,241 websites |
.de | 571 websites |
.org | 376 websites |
.co.uk | 220 websites |
.it | 187 websites |
.ru | 183 websites |
.net | 183 websites |
.pl | 176 websites |
.nl | 167 websites |
.fr | 148 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*******.org | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
**************.com | ![]() | ***,*** | |
*****************.it | ![]() | ***,*** | |
*********.ba | ![]() | ***,*** | |
*************.net | ![]() | ***,*** | |
*****.net | ![]() | ***,*** | |
******.com | ![]() | ***,*** |
FAQ