CVE · High

CVE-2015-1784 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.77.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-1784, CVE-2015-1785 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.77.3 Unrestricted Upload of File with Dangerous Type High 8.8 < 2.0.77.3 2.0.77.3 2015-03-25

CVE-2015-1784, CVE-2015-1785

The nextgen-gallery WordPress plugin before version 2.0.77.3 contains two security flaws that could enable an attacker to compromise the entire web application. One vulnerability stems from inadequate validation of files submitted by users, while the other results from missing protections against unauthorized HTTP requests.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.