CVE-2023-3279: NextGEN Gallery < 3.39 - Admin+ Local File Inclusion
Published Oct 16, 2023
·Updated
The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress<3.39
Event History
Oct 16, 2023
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this WordPress Plugin vulnerability?
The vulnerability ID of this WordPress Plugin vulnerability is CVE-2023-3279.
2
What is the severity level of CVE-2023-3279?
CVE-2023-3279 has a severity level of medium (4.9).
3
Which WordPress Plugin is affected by this vulnerability?
The WordPress Gallery Plugin WordPress plugin before version 3.39 is affected by this vulnerability.
4
What is the impact of CVE-2023-3279?
CVE-2023-3279 allows admin users to perform LFI attacks by exploiting the vulnerability in the WordPress Gallery Plugin.
5
How can this vulnerability be fixed?
To fix the vulnerability, it is recommended to update the WordPress Gallery Plugin to version 3.39 or later.