The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
We have discovered 45,762 live websites that are affected by CVE-2023-3155.
Product | ![]() |
Category | Photo Galleries |
Vulnerable Domains | 45,762 live websites (50.72% of NextGEN Gallery install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 262 versions ( 74.22% of all versions) |
![]() | 10,300 websites |
![]() | 7,319 websites |
![]() | 3,227 websites |
![]() | 2,836 websites |
![]() | 2,327 websites |
![]() | 1,877 websites |
![]() | 1,535 websites |
![]() | 1,394 websites |
![]() | 1,365 websites |
![]() | 752 websites |
.com | 15,046 websites |
.de | 4,525 websites |
.ru | 2,799 websites |
.pl | 1,882 websites |
.org | 1,854 websites |
.co.uk | 1,331 websites |
.cz | 1,213 websites |
.nl | 1,210 websites |
.it | 1,197 websites |
.net | 1,173 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**************.se | ![]() | **,*** | |
************.com | ![]() | **,*** | |
*****.*******.org | ![]() | **,*** | |
**********.cu | ![]() | **,*** | |
*********.org | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
************.com | ![]() | **,*** | |
****.fr | ![]() | **,*** | |
**********.com | ![]() | ***,*** | |
********.org | ![]() | ***,*** |
FAQ