CVE-2024-3097
WordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
Record summary
CVE-2024-3097 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
nextgen_galleryBrowse imagely / nextgen_galleryDefault status: unknown | CVE List | Through 3.59 | affected |
Photo Gallery, Sliders, Proofing and Themes – NextGEN GalleryBrowse smub / Photo Gallery, Sliders, Proofing and Themes – NextGEN GalleryDefault status: unaffected | CVE List | Through 3.59 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMNextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information DisclosureCVSS 5.3
The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.
Impact
Unauthenticated attackers can perform unauthorized actions within the NextGEN Gallery plugin.
Remediation
Update NextGEN Gallery to version 3.60 or later.
Source: ProjectDiscovery