The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 0.2. This is due to missing authorization checks on the vimeogallery_admin function hooked to admin_menu. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify arbitrary plugin settings via the action parameter.
No affected software listed.