CVE Database /
CVE-2023-48328
CVE · Medium
CVE-2023-48328 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-48328
|
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 3.39
|
3.39 |
2023-11-23 |
—
|
CVE-2023-48328
The NextGEN Gallery plugin for WordPress contained a cross-site request forgery vulnerability that could be exploited to trick authenticated users with elevated privileges into performing unintended actions on the site. A researcher named FearZzZz identified and disclosed this flaw, which was subsequently patched in version 3.39 and later releases. Users running versions prior to 3.39 should upgrade immediately to protect their installations from this attack vector.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings