CVE Database /
CVE-2022-38468
CVE · Medium
CVE-2022-38468 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.29
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-38468
|
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.29 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 3.29
|
3.29 |
2023-02-14 |
—
|
CVE-2022-38468
The NextGEN Gallery plugin for WordPress contained a cross-site request forgery flaw that allowed attackers to trick authenticated users with elevated privileges into performing unintended actions, such as changing administrator passwords. This vulnerability, discovered by Lana Codes, could enable unauthorized access to admin accounts by forcing password modifications through the compromised user's session. The issue was resolved in version 3.29 and users should update immediately to protect their installations.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings