CVE-2017-20207

CRITICAL EXPLOITED

Flickr Gallery <1.5.2 - Code Injection

Title source: llm

Description

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.

Scores

CVSS v3 9.8
EPSS 0.0033
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2017-10-02

Classification

CWE
CWE-502
Status published

Affected Products (1)

dancoulter/flickr_gallery < 1.5.2

Timeline

Published Oct 18, 2025
Tracked Since Feb 18, 2026