cleantalk
Vulnerabilities and Security Researches

WordPress Gallery Plugin – NextGEN Gallery, CVE-2023-3279

CVE, Research URL

CVE-2023-3279

Published on
Oct 17, 2023
Research Description
The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
Affected versions
Min -, max 3.39.
Status
vulnerable