CVE · Medium

CVE-2023-3279 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3279 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 3.39 3.39 2023-09-25

CVE-2023-3279

The NextGEN Gallery plugin for WordPress contains a local file inclusion flaw in versions up to 3.38 that can be exploited through the 'Select View' field within the plugin's developer tools. Attackers with administrator privileges can leverage this vulnerability to include and execute arbitrary files from the server, potentially running malicious PHP code. This capability allows attackers to circumvent security restrictions, access confidential information, or execute code when image uploads or other seemingly harmless file types are available for inclusion.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.