CVE-2017-20207

Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.


We have discovered 117 live websites that are affected by CVE-2017-20207.

Run a Free Instant Scan




Affected Software

Product  Flickr Gallery
Category Wordpress Plugins
Vulnerable Domains117 live websites (100% of Flickr Gallery install base)
Vulnerable Versions
  • from 0 through 1.5.3
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Oct 18, 2025
  • Updated - Oct 20, 2025

Credits

  • Matt Barry (finder)

Website Distribution by Country

Number of websites using CVE-2017-20207
United States46 websites



Germany16 websites
GB10 websites
Italy6 websites
Spain5 websites
Canada4 websites
France4 websites
Netherlands4 websites
Singapore3 websites
Austria2 websites

Website Distribution by TLD

Number of websites using CVE-2017-20207
.com55 websites
.net10 websites
.de10 websites
.org6 websites
.co.uk6 websites
.it4 websites
.at2 websites
.nl2 websites
.ca2 websites
.ru2 websites

Websites affected by CVE-2017-20207

Top websites that are affected by CVE-2017-20207. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.info Bulgaria***,***
******************.com Italy***,***
*******.com United States*,***,***
*******************.com United States*,***,***
****************.org United States*,***,***
**************.it Italy*,***,***
********.com United States*,***,***
******.com United States*,***,***
***********.com United States*,***,***
********.***.uk GB*,***,***
See full domain list

FAQ

CVE-2017-20207 is Deserialization of Untrusted Data in Flickr Gallery
A total of 117 websites have been identified as vulnerable to CVE-2017-20207, based on global website indexing conducted by WebTechSurvey.
The Flickr Gallery is affected by the CVE-2017-20207 vulnerability.
Flickr Gallery versions up to 1.5.3 are vulnerable to CVE-2017-20207.
CVE-2017-20207 is resolved in version 1.5.3 of Flickr Gallery.