CVE-2023-3279

All FrameworksWordPressCWE-OtherCVE-2023-3279

CVE-2023-3279

State: PUBLISHED · Published: 2023-10-16 · Updated: 2025-04-23 · Assigner: WPScan
Description
The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/3xxx/CVE-2023-3279.json