nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-20207 CVE-2017-20207
CRITICAL
Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection
Record summary
CVE-2017-20207 has a selected CVSS score of 9.8 (critical).
Description
The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 2, 2017 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Flickr GalleryBrowse Dan Coulter / Flickr GalleryDefault status: unaffected | CVE List | Before 1.5.3 | affected |
Flickr Gallery Plugin for WordPressBrowse Dan Coulter / Flickr Gallery Plugin for WordPress | VulnCheck | Version data not supplied | |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/1737576/flickr-gallery wordfence.com
https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/b52ae51d-7b9a-4047-82bf-723ea87d2375?source=cve