CVE · High

CVE-2023-3155 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3155 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Files or Directories Accessible to External Parties High 7.2 < 3.39 3.39 2023-09-25

CVE-2023-3155

The NextGEN Gallery plugin contained an arbitrary file deletion vulnerability that could permit attackers to remove files from an affected website, potentially causing site breakage or complete dysfunction if critical files were targeted. This flaw was identified by Linwz from DEVCORE and has been patched in version 3.39 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.