CVE · High

CVE-2016-10889 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2016-6565, CVE-2016-10889 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57 Improper Input Validation High 7.5 < 2.1.57 2.1.57 2016-11-15

CVE-2016-6565, CVE-2016-10889

The NextGEN Gallery plugin for WordPress versions before 2.1.57 contains an input validation flaw in the cssfile parameter when processing HTTP POST requests. An authenticated attacker could exploit this weakness to access unauthorized files on the server or, under certain server configurations, execute arbitrary code.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.