CVE · Medium

CVE-2022-38468 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.29

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-38468 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.29 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.29 3.29 2023-02-14

CVE-2022-38468

The NextGEN Gallery plugin for WordPress contained a cross-site request forgery flaw that allowed attackers to trick authenticated users with elevated privileges into performing unintended actions, such as changing administrator passwords. This vulnerability, discovered by Lana Codes, could enable unauthorized access to admin accounts by forcing password modifications through the compromised user's session. The issue was resolved in version 3.29 and users should update immediately to protect their installations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.