CVE-2024-3097: WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getitem function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3097?
CVE-2024-3097 is considered a high severity vulnerability due to unauthorized data access risks.
How do I fix CVE-2024-3097?
To fix CVE-2024-3097, update the NextGEN Gallery plugin to version 3.59.1 or later.
Which WordPress versions are affected by CVE-2024-3097?
CVE-2024-3097 affects all versions of the NextGEN Gallery plugin up to and including 3.59.
What data is at risk due to CVE-2024-3097?
CVE-2024-3097 allows unauthenticated attackers to potentially extract sensitive data.
What is the cause of CVE-2024-3097?
CVE-2024-3097 is caused by a missing capability check in the get_item function of the NextGEN Gallery plugin.