CVE-2023-48328: WordPress NextGEN Gallery Plugin <= 3.37 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-48328?
CVE-2023-48328 is a Cross-Site Request Forgery (CSRF) vulnerability found in the WordPress NextGEN Gallery Plugin version 3.37 and below.
How does CVE-2023-48328 impact the WordPress NextGEN Gallery Plugin?
CVE-2023-48328 allows attackers to perform unauthorized actions on behalf of a user, potentially leading to account compromise or data loss.
What is the severity of CVE-2023-48328?
The severity of CVE-2023-48328 is high, with a CVSS score of 8.8.
How can I fix CVE-2023-48328?
To fix CVE-2023-48328, update your WordPress NextGEN Gallery Plugin to version 3.39 or above.
Where can I find more information about CVE-2023-48328?
More information about CVE-2023-48328 can be found at the following link: [CVE-2023-48328](https://patchstack.com/database/vulnerability/nextgen-gallery/wordpress-wordpress-gallery-plugin-nextgen-gallery-plugin-3-37-cross-site-request-forgery-csrf-vulnerability?_s_id=cve).