WordPress Plugin Vulnerabilities

NextGen Gallery <= 3.1.5 - Authenticated PHP Object Injection

Description

Legacy serialization handling allows unserialize of user input for low privileged users, leading to RCE.

Affects Plugins

Fixed in 3.1.6

References

Classification

Type
OBJECT INJECTION
CWE
CVSS

Miscellaneous

Original Researcher
Slavco
Submitter
Slavco
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2019-02-05 (about 7 years ago)
Added
2019-02-05 (about 7 years ago)
Last Updated
2021-02-08 (about 5 years ago)

Other