CVE · High

CVE-2016-6565 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2016-6565, CVE-2016-10889 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57 Improper Input Validation High 7.5 < 2.1.57 2.1.57 2016-11-15

CVE-2016-6565, CVE-2016-10889

The Imagely NextGen Gallery plugin before version 2.1.57 contains insufficient input validation on the cssfile parameter when processing HTTP POST requests, potentially enabling authenticated users to read sensitive files from the server or execute arbitrary code depending on how the server is configured.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.