Vulnerability Description
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagely | Nextgen Gallery | < 3.39 |
References
- https://wpscan.com/vulnerability/ed099489-1db4-4b42-9f72-77de39c9e01eExploitThird Party Advisory
- https://wpscan.com/vulnerability/ed099489-1db4-4b42-9f72-77de39c9e01eExploitThird Party Advisory
FAQ
What is CVE-2023-3154?
CVE-2023-3154 is a vulnerability with a CVSS score of 7.5 (HIGH). The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to acce...
How severe is CVE-2023-3154?
CVE-2023-3154 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3154?
Check the references section above for vendor advisories and patch information. Affected products include: Imagely Nextgen Gallery.