
🚨 CVE-2024-11103: Contest Gallery <= 24.0.7 - Unau... Zero validation on password reset = instant admin takeover on 100k+ WordPress sites running this plugin - pure unauthen... https://zerodaysignal.com/vulnerability/CVE-2024-11103 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces CVE‑2024‑11103, a flaw in Contest Gallery allowing unrestricted admin takeover via password reset, reportedly affecting over 100,000 WordPress sites. No PoC, exploit code, or patch is provided.
