← back
CVE-2017-20207criticalobserved exploitationCWE-502

Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.8epss 0.7%
from disclosure to weapon
Published on NVDOct 18
VulnCheckOct 2
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
yesVulnCheck
The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H