WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Nextgen Gallery?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Nextgen Gallery — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: nextgen-gallery
  • 400000+ instalaciones activas

galleryimage galleryphoto galleryslideshowwordpress gallery plugin

Estado de mantenimiento

  • Última versión conocida: 4.2.3
  • Requiere PHP: 7.0+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

33 CVEs conocidos registrados para Nextgen Gallery.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-6566 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.2.1 Elusión de autorización mediante una clave controlada por el usuario Media 4,3 < 4.2.1 4.2.1 2026-05-19 ✓ corregido en la última versión
CVE-2025-13641 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.0 Control incorrecto del nombre de archivo en una sentencia include/require de PHP (inclusión remota de archivos PHP / RFI) Alta 8,8 < 4.0.0 4.0.0 2025-12-17 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.12 Media 6,4 < 3.59.12 3.59.12 2025-07-03 ✓ corregido en la última versión
CVE-2024-10545 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Baja 3,5 < 3.59.9 3.59.9 2025-02-04 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.59.5 3.59.5 2024-12-03 ✓ corregido en la última versión
CVE-2024-6393 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.59.5 3.59.5 2024-11-04 ✓ corregido en la última versión
CVE-2024-39627 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 3.59.4 3.59.4 2024-07-22 ✓ corregido en la última versión
CVE-2024-5442 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 3.59.3 3.59.3 2024-06-22 ✓ corregido en la última versión

CVE-2026-6566

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 4.2.0. This is due to insufficient object-level authorization in the image deletion REST flow where the permission callback for DELETE /imagely/v1/images/{id} only checks 'NextGEN Manage gallery' permissions and does not enforce gallery ownership or 'NextGEN Manage others gallery' permissions. This makes it possible for authenticated attackers, with Subscriber-level privileges and 'NextGEN Manage gallery' capability, to delete gallery images belonging to other users as well as their associated image files from disk when deleteImg is enabled (default).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-13641

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.59.12 via the 'template' shortcode parameter. This is due to insufficient path validation that allows absolute paths to be provided. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server, bypassing web server restrictions like .htaccess. Successful exploitation could lead to information disclosure, code execution in the WordPress context, and potential remote code execution if combined with arbitrary file upload capabilities.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-10545

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.59.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-6393

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.39.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-39627

The NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.59.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-5442

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery settings in all versions up to, and including, 3.59.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 58 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-2744 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,3 < 3.59.1 3.59.1 2024-04-26 ✓ corregido en la última versión
CVE-2024-3097 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.1 Falta de control de autorización Media 5,3 < 3.59.1 3.59.1 2024-04-05 ✓ corregido en la última versión
CVE-2023-48328 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.39 3.39 2023-11-23 ✓ corregido en la última versión
CVE-2023-3155 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Archivos o directorios accesibles a terceros Alta 7,2 < 3.39 3.39 2023-09-25 ✓ corregido en la última versión
CVE-2023-3154 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Deserialización de datos no confiables Alta 7,5 < 3.39 3.39 2023-09-25 ✓ corregido en la última versión
CVE-2023-3279 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 4,9 < 3.39 3.39 2023-09-25 ✓ corregido en la última versión
CVE-2023-33999 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.4.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 3.4.7 3.4.7 2023-07-18 ✓ corregido en la última versión
CVE-2022-38468 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.29 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.29 3.29 2023-02-14 ✓ corregido en la última versión
CVE-2020-35942 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.5.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 8,8 < 3.5.0 3.5.0 2020-12-17 ✓ corregido en la última versión
CVE-2020-35943 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.5.0 Falsificación de petición en sitios cruzados (CSRF) Media 6,5 < 3.5.0 3.5.0 2020-12-17 ✓ corregido en la última versión
CVE-2019-14314 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.2.11 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Crítica 9,8 < 3.2.11 3.2.11 2019-08-27 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.7 Desconocido < 3.1.7 3.1.7 2019-03-02 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.7 Desconocido < 3.1.7 3.1.7 2019-02-25 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.6 Desconocido < 3.1.6 3.1.6 2019-02-04 ✓ corregido en la última versión
CVE-2018-7586 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.2.50 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 7,5 < 2.2.50 2.2.50 2018-03-01 ✓ corregido en la última versión
CVE-2018-1000172 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.2.45 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 2.2.45 2.2.45 2018-02-14 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.79 Desconocido < 2.1.79 2.1.79 2017-02-17 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.60 Desconocido < 2.1.60 2.1.60 2016-11-28 ✓ corregido en la última versión
CVE-2016-10889 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Crítica 9,8 < 2.1.57 2.1.57 2016-11-15 ✓ corregido en la última versión
CVE-2016-6565 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57 Validación incorrecta de la entrada Alta 7,5 < 2.1.57 2.1.57 2016-11-15 ✓ corregido en la última versión
CVE-2015-9228 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.15 Carga de archivos sin restricción de tipo peligroso Alta 8,8 < 2.1.15 2.1.15 2015-12-23 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.9 Desconocido < 2.1.9 2.1.9 2015-10-07 ✓ corregido en la última versión
CVE-2015-9229 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.23 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 2.1.23 2.1.23 2015-09-14 ✓ corregido en la última versión
CVE-2015-9537 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.10 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 2.1.10 2.1.10 2015-08-31 ✓ corregido en la última versión
CVE-2015-9538 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.15 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,5 < 2.1.15 2.1.15 2015-08-28 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.9 Desconocido < 2.1.9 2.1.9 2015-08-28 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.66 Desconocido < 2.0.66 2.0.66 2015-05-15 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.7 Desconocido < 2.0.7 2.0.7 2015-05-15 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.8 Desconocido < 1.9.8 1.9.8 2015-05-15 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.0 Desconocido < 2.0.0 2.0.0 2015-05-15 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.0 Desconocido < 2.0.0 2.0.0 2015-05-15 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.1 Desconocido < 1.9.1 1.9.1 2015-05-15 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.8.4 Desconocido < 1.8.4 1.8.4 2015-05-15 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.7.4 Desconocido < 1.7.4 1.7.4 2015-05-15 ✓ corregido en la última versión
CVE-2015-1784 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.77.3 Carga de archivos sin restricción de tipo peligroso Alta 8,8 < 2.0.77.3 2.0.77.3 2015-03-25 ✓ corregido en la última versión
CVE-2015-1785 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.77.3 Falsificación de petición en sitios cruzados (CSRF) Media 6,5 < 2.0.77.3 2.0.77.3 2015-03-25 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.66 Desconocido < 2.0.66 2.0.66 2014-05-20 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.1 Desconocido < 2.0.1 2.0.1 2014-02-19 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.7 Desconocido < 2.0.7 2.0.7 2014-02-18 ✓ corregido en la última versión
CVE-2013-3684 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.13 Carga de archivos sin restricción de tipo peligroso Crítica 9,8 < 1.9.13 1.9.13 2013-06-12 ✓ corregido en la última versión
CVE-2013-0291 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] >= 1.9.10 - <= 1.9.11 Exposición de información sensible a un actor no autorizado Alta 7,5 1.9.10–1.9.11 1.9.11 2013-02-14 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.11 Desconocido < 1.9.11 1.9.11 2013-01-08 ✓ corregido en la última versión
CVE-2012-3414 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 1.9.7 1.9.7 2012-06-14 ✓ corregido en la última versión
CVE-2010-1186 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.5.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 1.5.2 1.5.2 2010-04-06 ✓ corregido en la última versión
CVE-2008-7175 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] <= 0.96 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 0.96 0.96 2008-06-07 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 3.59.5 3.59.5 0000-00-00 ✓ corregido en la última versión
CVE-2026-1463 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.5 Desconocido < 4.0.5 4.0.5 0000-00-00 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.7 Desconocido < 3.1.7 3.1.7 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.6 Desconocido < 3.1.6 3.1.6 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.79 Desconocido < 2.1.79 2.1.79 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.9 Desconocido < 2.1.9 2.1.9 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.0 Desconocido < 2.0.0 2.0.0 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.7.4 Desconocido < 1.7.4 1.7.4 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.8 Desconocido < 1.9.8 1.9.8 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.8.4 Desconocido < 1.8.4 1.8.4 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.1 Desconocido < 1.9.1 1.9.1 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.7 Desconocido < 2.0.7 2.0.7 ✓ corregido en la última versión
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.66 Desconocido < 2.0.66 2.0.66 ✓ corregido en la última versión

CVE-2024-2744

The NextGEN Gallery – Create an Amazing Photo Gallery in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.59 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-3097

Update the WordPress NextGEN Gallery plugin to the latest available version (at least 3.59.1). Peng Zhou discovered and reported this Broken Access Control vulnerability in WordPress NextGEN Gallery Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 3.59.1. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-48328

Update the WordPress NextGEN Gallery plugin to the latest available version (at least 3.39). FearZzZz discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress NextGEN Gallery Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.39.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-3155

Update the WordPress NextGEN Gallery plugin to the latest available version (at least 3.39). Linwz from DEVCORE discovered and reported this Arbitrary File Deletion vulnerability in WordPress NextGEN Gallery Plugin. This could allow a malicious actor to delete files from your website. If core files are deleted from your website, it could cause your site to break and stop functioning. This vulnerability has been fixed in version 3.39.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-3154

The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 3.38 via deserialization of untrusted input in the gallery_edit function. This makes it possible for authenticated attackers, with administrative-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-3279

The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.38 via the 'Select View' field in the plugin's developer tools. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-33999

Update the WordPress NextGEN Gallery plugin to the latest available version. Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress NextGEN Gallery Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.4.7.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-38468

Update the WordPress NextGEN Gallery plugin to the latest available version (at least 3.29). Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress NextGEN Gallery Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 3.29.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2020-35942

It was possible to bypass the "is_authorized_request" function used to control access to plugin settings by sending a request without a nonce parameter. This could be used to upload arbitrary code to a CSS file with a double extension (e.g. file.php.css), and could also be used to include the uploaded file as a gallery template, resulting in RCE and XSS when visiting a gallery using the selected template.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2020-35943

It was possible to bypass the "validate_ajax_request" function used to control access to ajax functions by sending a request without a nonce parameter. This could be used to upload arbitrary code to an image file. Although the uploaded file must be a valid image, it is possible to include PHP code in a valid image, which would be executed if included using the vulnerability in CVE-2020-35942

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2019-14314

A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2018-7586

The changelog states: "Secured: Gallery paths and the ability to manage tags Kudos: ElevenPaths (Telefonica cibersecurity Unit)"

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2018-1000172

Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image in the administrator page. This vulnerability appears to have been fixed in 2.2.45.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2016-10889

The WordPress Gallery Plugin – NextGEN Gallery WordPress plugin was affected by an Authenticated Local File Inclusion (LFI) & SQLi security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2016-6565

The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2015-9228

In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2015-9229

In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2015-9537

The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2015-9538

The WordPress Gallery Plugin – NextGEN Gallery WordPress plugin was affected by a Path Traversal security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2015-1784

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2015-1785

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2013-3684

NextGEN Gallery plugin is prone to an arbitrary file upload vulnerability. It allows an attacker to upload arbitrary files to the affected computer. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2013-0291

This NextGEN Gallery plugin is prone to a path-disclosure vulnerability. It allows anr attacker to obtain sensitive information that may lead to further attacks. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2012-3414

The NextGen Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via swfupload.swf in versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2010-1186

This NextGEN Gallery plugin is prone to a cross-site scripting vulnerability. It is really popular plugin for the WordPress content management system, usually found as a blogging platform. The vulnerability manipulates the mode parameter of the xml/media-rss.php script and it results that unsanitized imput can be crafted into an attack by a malicious user.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2008-7175

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field for galleries in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-1463

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Mantén Nextgen Gallery actualizado — 4.2.3 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.