CVE · Medium

CVE-2024-39627 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-39627 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.59.4 3.59.4 2024-07-22

CVE-2024-39627

The NextGEN Gallery plugin through version 3.59.3 contains a stored cross-site scripting flaw resulting from inadequate input validation and output encoding. Administrators and higher-privileged users can inject malicious scripts into pages that execute when other users view the affected content. This vulnerability only affects WordPress multisite setups or installations where the unfiltered_html capability has been restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.