Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.8epss 0.7%
from disclosure to weapon
Published on NVDOct 18
VulnCheckOct 2
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
yesVulnCheck
The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Dan Coulter · Flickr Gallery