Cross-Site Request Forgery Vulnerability in Nilesh Shiragave WordPress Gallery Plugin
CVE-2025-23842
7.1HIGH
What is CVE-2025-23842?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Gallery Plugin by Nilesh Shiragave. This flaw could allow an attacker to trick users into executing unwanted actions on a web application where they are authenticated, potentially leading to unauthorized content manipulation or data exposure. The affected versions range from an unspecified release before version 1.4, necessitating immediate attention to mitigate any security risks associated with this vulnerability.
Affected Version(s)
WordPress Gallery Plugin <= 1.4