CVE Database /
CVE-2023-3279
CVE · Medium
CVE-2023-3279 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-3279
|
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
4.9
|
< 3.39
|
3.39 |
2023-09-25 |
—
|
CVE-2023-3279
The NextGEN Gallery plugin for WordPress contains a local file inclusion flaw in versions up to 3.38 that can be exploited through the 'Select View' field within the plugin's developer tools. Attackers with administrator privileges can leverage this vulnerability to include and execute arbitrary files from the server, potentially running malicious PHP code. This capability allows attackers to circumvent security restrictions, access confidential information, or execute code when image uploads or other seemingly harmless file types are available for inclusion.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings