CVE-2023-3155

NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.


We have discovered 45,762 live websites that are affected by CVE-2023-3155.

Test my site




Affected Software

Product  NextGEN Gallery
Category Photo Galleries
Vulnerable Domains45,762 live websites (50.72% of NextGEN Gallery install base)
Vulnerable Versions
  • from 0 before 3.39
Vulnerable Versions Count262 versions ( 74.22% of all versions)


Common Weakness Enumeration

CWE-552 Files or Directories Accessible to External Parties



Details

  • Published - Oct 16, 2023
  • Updated - Aug 2, 2024

Credits

  • Linwz from DEVCORE (finder)
  • WPScan (coordinator)

CVE-2023-3155 usage by Country

United States10,300 websites



Germany7,319 websites
Russia3,227 websites
France2,836 websites
Poland2,327 websites
GB1,877 websites
Italy1,535 websites
Netherlands1,394 websites
Czech Republic1,365 websites
Hungary752 websites

CVE-2023-3155 usage by TLD

.com15,046 websites
.de4,525 websites
.ru2,799 websites
.pl1,882 websites
.org1,854 websites
.co.uk1,331 websites
.cz1,213 websites
.nl1,210 websites
.it1,197 websites
.net1,173 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-3155

Top websites that are affected by CVE-2023-3155. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.se Sweden**,***
************.com Italy**,***
*****.*******.org United States**,***
**********.cu Cuba**,***
*********.org Spain**,***
*******.com Singapore**,***
************.com United States**,***
****.fr France**,***
**********.com United States***,***
********.org France***,***
See full domain list

FAQ

CVE-2023-3155 is Files or Directories Accessible to External Parties in NextGEN Gallery
A total of 45,762 websites have been identified as vulnerable to CVE-2023-3155, discovered through global website indexing conducted by WebTechSurvey.
NextGEN Gallery is susceptible to CVE-2023-3155 vulnerability.
NextGEN Gallery versions before 3.39 are vulnerable to CVE-2023-3155.
Version 3.39 of NextGEN Gallery addresses the CVE-2023-3155 security vulnerability.