WP Simple Galleries [wp-simple-galleries] <= 1.34 (unfixed + closed)
unknown
[en] The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.34 via deserialization of untrusted input from the 'wpsimplegallery_gallery' post meta via 'wpsgallery' shortcode. This allows authenticated attackers, with contributor-level permissions and above...
- Affected:
- up to 1.34
- Fix:
- No patched version reported
- Disclosed:
- Oct 30, 2023
CVE-2023-5583 on NVD →
WP Simple Galleries <= 1.34 - Authenticated (Contributor+) PHP Object Injection
high
The WP Simple Galleries plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.34 via deserialization of untrusted input from the 'wpsimplegallery_gallery' post meta via 'wpsgallery' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to...
- CVSS:
- 8.8
- Affected:
- up to 1.34
- Fix:
- No patched version reported
- Disclosed:
- Oct 29, 2023
CVE-2023-5583 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database