CVE · Medium

CVE-2020-35943 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-35943 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.5.0 Cross-Site Request Forgery (CSRF) Medium 6.5 < 3.5.0 3.5.0 2020-12-17

CVE-2020-35943

The NextGEN Gallery plugin before version 3.5.0 contained a security flaw in its "validate_ajax_request" function that could be circumvented by submitting requests that omitted the nonce parameter, thereby bypassing intended access controls. An attacker could exploit this weakness to upload files containing arbitrary code disguised as images, and if such a file were subsequently included through the vulnerability described in CVE-2020-35942, the embedded PHP code would be executed on the server.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.