CVE · High

CVE-2023-3154 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3154 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Deserialization of Untrusted Data High 7.5 < 3.39 3.39 2023-09-25

CVE-2023-3154

The NextGEN Gallery plugin for WordPress contains a PHAR deserialization vulnerability affecting versions up to 3.38 in the gallery_edit function that permits authenticated administrators to inject malicious PHP objects through untrusted input deserialization. While the plugin itself lacks a gadget chain for exploitation, the presence of a usable POP chain in other installed plugins or themes could enable attackers to execute arbitrary code, exfiltrate sensitive information, or remove files from the system. The vulnerability requires administrative privileges to exploit directly.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.