CVE Database /
CVE-2020-35943
CVE · Medium
CVE-2020-35943 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.5.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-35943
|
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.5.0 |
Cross-Site Request Forgery (CSRF) |
Medium
6.5
|
< 3.5.0
|
3.5.0 |
2020-12-17 |
—
|
CVE-2020-35943
The NextGEN Gallery plugin before version 3.5.0 contained a security flaw in its "validate_ajax_request" function that could be circumvented by submitting requests that omitted the nonce parameter, thereby bypassing intended access controls. An attacker could exploit this weakness to upload files containing arbitrary code disguised as images, and if such a file were subsequently included through the vulnerability described in CVE-2020-35942, the embedded PHP code would be executed on the server.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings