CVE-2023-3155: NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete
Published Oct 16, 2023
·Updated
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the galleryedit function, allowing an attacker to access arbitrary resources on the server.
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress<3.39
Event History
Oct 16, 2023
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-3155.
2
What is the severity of CVE-2023-3155?
The severity of CVE-2023-3155 is high with a score of 7.2.
3
What is affected by CVE-2023-3155?
The WordPress Gallery Plugin version before 3.39 is affected by CVE-2023-3155.
4
What is the impact of CVE-2023-3155?
CVE-2023-3155 allows an attacker to access arbitrary resources on the server through Arbitrary File Read and Delete.
5
How can I fix CVE-2023-3155?
To fix CVE-2023-3155, it is recommended to update to the latest version of the WordPress Gallery Plugin.