← WordPress Vulnerabilities
WordPress security by component

WordPress Picture / Portfolio / Media Gallery

WordPress Picture / Portfolio / Media Gallery is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 19, 2024; the highest CVE/CNA score is 9.3.

Plugin slug: nimble-portfolio

CVE-2024-5021: WordPress Picture / Portfolio / Media Gallery: Server-side request forgery

WordPress Picture / Portfolio / Media Gallery is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.

PublishedJun 19, 2024
Safe version guidanceSee mitigation notes
Safe version
Jun 19, 2024 CVE-2024-5021
WordPress Picture / Portfolio / Media Gallery: Server-side request forgery
WordPress Picture / Portfolio / Media Gallery is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE9.3
NVDPending