CVE · High

CVE-2018-7586 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.2.50

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-7586 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.2.50 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 2.2.50 2.2.50 2018-03-01

CVE-2018-7586

A path traversal vulnerability in NextGEN Gallery versions prior to 2.2.50 allowed unauthorized access to gallery paths and tag management functionality. The plugin failed to properly secure these features, potentially enabling attackers to manipulate gallery data and access sensitive path information. This issue was addressed in version 2.2.50 following disclosure by ElevenPaths, the cybersecurity division of Telefonica.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.