CVE-2023-3155

NextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.


We have discovered 31,100 live websites that are affected by CVE-2023-3155.

Run a Free Instant Scan




Affected Software

Product  NextGEN Gallery
Category Photo Galleries
Vulnerable Domains31,100 live websites (42% of NextGEN Gallery install base)
Vulnerable Versions
  • from 0 through 3.39
Vulnerable Versions Count191 versions ( 89% of all versions)


Common Weakness Enumeration

CWE-552 Files or Directories Accessible to External Parties



Details

  • Published - Oct 16, 2023
  • Updated - Apr 23, 2025

Credits

  • Linwz from DEVCORE (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-3155
United States6,014 websites



Germany4,684 websites
Russia2,217 websites
Italy2,188 websites
France1,729 websites
Poland1,455 websites
GB1,388 websites
Czech Republic1,374 websites
Netherlands943 websites
Spain538 websites

Website Distribution by TLD

Number of websites using CVE-2023-3155
.com9,906 websites
.de3,099 websites
.ru1,857 websites
.it1,477 websites
.org1,270 websites
.cz1,212 websites
.pl1,123 websites
.co.uk899 websites
.nl809 websites
.net786 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-3155

Top websites that are affected by CVE-2023-3155. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.*******.org United States**,***
*********.org Spain**,***
*******.com Singapore**,***
************.com United States**,***
****.fr France**,***
**********.com United States***,***
********.org France***,***
********.com Russia***,***
********.org United States***,***
***.**.**.uk GB***,***
See full domain list

FAQ

CVE-2023-3155 is Files or Directories Accessible to External Parties in NextGEN Gallery
A total of 31,100 websites have been identified as vulnerable to CVE-2023-3155, based on global website indexing conducted by WebTechSurvey.
The NextGEN Gallery is affected by the CVE-2023-3155 vulnerability.
NextGEN Gallery versions up to 3.39 are vulnerable to CVE-2023-3155.
CVE-2023-3155 is resolved in version 3.39 of NextGEN Gallery.