CVE · Medium

CVE-2024-6393 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6393 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.59.5 3.59.5 2024-11-04

CVE-2024-6393

The NextGEN Gallery plugin for WordPress contains a security flaw that allows malicious administrators to embed unauthorized code into certain settings within the admin area, which can then be executed by other users when they access those specific pages. This issue arises from inadequate filtering of user input and insufficient protection against injected scripts in affected versions up to 3.39.4. The vulnerability is limited to multi-site setups where unfiltered HTML has been disabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.