Gallery Plugin Vulnerable to PHP Object Injection
CVE-2024-11501
What is CVE-2024-11501?
The Gallery plugin for WordPress exposes a vulnerability to PHP Object Injection across all versions up to and including 1.3. This vulnerability arises from the deserialization of untrusted input from the wd_gallery_$id parameter, enabling authenticated attackers with Contributor-level privileges or higher to inject PHP objects into the application. While no known PHP Object Protocol chain exists within the vulnerable plugin itself, the presence of such a chain through additional plugins or themes could potentially empower an attacker to delete arbitrary files, access sensitive data, or execute malicious code, heightening the overall security risks for affected WordPress sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Gallery * <= 1.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved