CVE-2023-3154: NextGEN Gallery < 3.39 - Admin+ PHAR Deserialization
Published Oct 16, 2023
·Updated
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the galleryedit function, allowing an attacker to access arbitrary resources on the server.
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress<3.39
Event History
Oct 16, 2023
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-3154?
CVE-2023-3154 is a vulnerability in the WordPress Gallery Plugin WordPress plugin before version 3.39 that allows an attacker to access arbitrary resources on the server.
2
How severe is CVE-2023-3154?
CVE-2023-3154 has a severity rating of high, with a CVSS score of 7.5.
3
Which software is affected by CVE-2023-3154?
The Imagely Nextgen Gallery WordPress plugin versions up to and excluding 3.39 are affected by CVE-2023-3154.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-3154?
CVE-2023-3154 is associated with CWE-502.
5
How can the CVE-2023-3154 vulnerability be fixed?
To fix CVE-2023-3154, update the WordPress Gallery Plugin WordPress plugin to version 3.39 or higher.