CVE-2023-3154
The NextGEN Gallery plugin for WordPress contains a PHAR deserialization vulnerability affecting versions up to 3.38 in the gallery_edit function that permits authenticated administrators to inject malicious PHP objects through untrusted input deserialization. While the plugin itself lacks a gadget chain for exploitation, the presence of a usable POP chain in other installed plugins or themes could enable attackers to execute arbitrary code, exfiltrate sensitive information, or remove files from the system. The vulnerability requires administrative privileges to exploit directly.
Based on public CVE data (MITRE/NVD).