← Vulnerability feed

Vulnerability record · CVE-2024-3097 · published 9 April 2024

CVE-2024-3097: Imagely nextgen gallery missing authorization vulnerability

Imagely · Nextgen Gallery

The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.

5.3 CVSS 3.1 Medium EPSS 38% · top 1.5% CWE-862 · Missing authorization
5.3CVSS 3.1 base score
38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3097 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-3684Imagely nextgen gallery unrestricted file upload vulnerabilityNextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file uploadEPSS 19%9.8CVE-2019-14314Imagely nextgen gallery sql injection vulnerabilityA SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability…EPSS 43%9.8CVE-2016-10889Imagely nextgen gallery sql injection vulnerabilityThe nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.EPSS 1.8%8.8CVE-2023-48328Imagely nextgen gallery cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue af…EPSS 0.27%8.8CVE-2015-1784Imagely nextgen gallery unrestricted file upload vulnerabilityIn nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica…EPSS 2.0%8.8CVE-2020-35942Imagely nextgen gallery cross-site scripting vulnerabilityA Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via se…EPSS 1.4%8.8CVE-2015-9228Imagely nextgen gallery unrestricted file upload vulnerabilityIn post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a fil…EPSS 3.7%7.5CVE-2023-3154Imagely nextgen gallery vulnerabilityThe WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `g…EPSS 0.70%

Source: NIST National Vulnerability Database (record CVE-2024-3097), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.