S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jun 13, 2024

CVE-2024-3097 Scanner

CVE-2024-3097 scanner - Unauthenticated Information Disclosure vulnerability in NextGEN Gallery

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-3097
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. This makes it possible for unauthenticated attackers to extract sensitive data including EXIF and other metadata of any image uploaded through the plugin.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Photo Gallery, Sliders, Proofing and Themes – NextGEN Galleryby smub
0
nextgen_galleryby imagely
0
Updated Aug 22, 2026View on NVD →
Detail

NextGEN Gallery is a popular WordPress plugin used by website owners to manage and display image galleries. It is widely utilized by photographers, artists, and bloggers to showcase their visual content. The plugin allows users to upload, organize, and publish galleries with ease. Additionally, it supports various gallery styles and provides an intuitive interface for managing images. The vulnerability check focuses on unauthorized access to sensitive data within the plugin.

The vulnerability in NextGEN Gallery allows unauthenticated attackers to access sensitive image metadata. This occurs due to a missing capability check in the get_item function. Exploiting this flaw, attackers can extract EXIF and other metadata from any uploaded image. The vulnerability affects versions up to and including 3.59.

The NextGEN Gallery plugin lacks proper authorization checks in the get_item function, specifically in the REST API endpoint. The vulnerable endpoint is "/wp-json/ngg/v1/admin/block/image/1", which can be accessed without authentication. The plugin's failure to verify user permissions allows attackers to retrieve sensitive information. The metadata extracted includes EXIF data, potentially exposing location and camera details. Proper authorization checks are missing, making the data vulnerable to unauthorized access.

Exploitation of this vulnerability can lead to the exposure of sensitive image metadata. Attackers may use this information to gain insights into user activity, including location data from EXIF metadata. This could result in privacy breaches and unauthorized tracking of individuals. Furthermore, the disclosure of metadata might aid in planning further attacks or social engineering schemes. The vulnerability poses a risk to user privacy and security.

Join the S4E platform to ensure your digital assets are secure. Our comprehensive scans detect vulnerabilities like unauthorized information disclosure in widely used plugins such as NextGEN Gallery. By becoming a member, you'll receive detailed reports, timely alerts, and expert guidance on remediation. Protect your website, maintain user trust, and stay ahead of potential threats with our proactive security measures. S4E helps you safeguard your online presence effortlessly.

References:

Solution Advice
  • Update NextGEN Gallery to the latest version.
  • Implement proper authorization checks for REST API endpoints.
  • Regularly review and audit plugin configurations.
  • Restrict access to sensitive data based on user roles and permissions.
  • Monitor and apply security patches promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.