QID 730053

Date Published: 2021-04-20

QID 730053: Wordpress NextGen Gallery plugin Multiple Vulnerabilities

NextGEN Gallery is a popular WordPress plugin designed to create highly responsive image galleries.

CVE-2020-35942: A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS.
CVE-2020-35943: A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload.

Affected Version:
All versions prior to 3.5.0:
QID Detection Logic:
The QID send a request, check the nextgen plugin version info from readme.txt file.

Successful exploitation of the vulnerability could allow and attacker to perform XSS (Cross Site Scripting)Remote Code Execution on a website.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to the fixed versions of WordPress Gallery Plugin NextGEN Gallery 3.5.0 to remediate the vulnerability.
    For more Information Please visit WordPress plugin

    CVEs related to QID 730053

    Software Advisories
    Advisory ID Software Component Link
    NextGEN URL Logo wordpress.org/plugins/nextgen-gallery/