PLUGIN SECURITY

Is Nextgen Gallery safe?

The most popular gallery plugin that lets you create galleries and albums in seconds.

What this plugin does

  • Slug: nextgen-gallery
  • Author: Syed Balkhi
  • 300000+ active installs
  • 86/100 rating (4339 reviews on wordpress.org)
  • 46005056 all-time downloads
  • On WordPress.org since 2007-04-23

galleryimage galleryphoto galleryslideshowwordpress gallery plugin

Maintenance status

  • Latest known version: 4.2.4
  • Last updated: 2026-08-21 6:17pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

38 known CVEs on file for Nextgen Gallery.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9059 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.2.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 4.2.1 4.2.1 2026-05-20 ✓ fixed in latest
CVE-2026-28141 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.2.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 4.2.4 4.2.4 2026-05-20 ✓ fixed in latest
CVE-2026-6566 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.2.1 Authorization Bypass Through User-Controlled Key Medium 4.3 < 4.2.1 4.2.1 2026-05-19 ✓ fixed in latest
CVE-2025-13641 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.0 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 8.8 < 4.0.0 4.0.0 2025-12-17 ✓ fixed in latest
CVE-2024-10545 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Low 3.5 < 3.59.9 3.59.9 2025-02-04 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.59.5 3.59.5 2024-12-03 ✓ fixed in latest
CVE-2024-6393 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.59.5 3.59.5 2024-11-04 ✓ fixed in latest
CVE-2024-39627 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.59.4 3.59.4 2024-07-22 ✓ fixed in latest
+ 75 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5442 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 3.59.3 3.59.3 2024-06-22 ✓ fixed in latest
CVE-2024-2744 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.3 < 3.59.1 3.59.1 2024-04-26 ✓ fixed in latest
CVE-2024-3097 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.1 Missing Authorization Medium 5.3 < 3.59.1 3.59.1 2024-04-05 ✓ fixed in latest
CVE-2023-48328 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.39 3.39 2023-11-23 ✓ fixed in latest
CVE-2023-3155 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Files or Directories Accessible to External Parties High 7.2 < 3.39 3.39 2023-09-25 ✓ fixed in latest
CVE-2023-3154 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Deserialization of Untrusted Data High 7.5 < 3.39 3.39 2023-09-25 ✓ fixed in latest
CVE-2023-3279 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.39 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 3.39 3.39 2023-09-25 ✓ fixed in latest
CVE-2023-33999 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.4.7 3.4.7 2023-07-18 ✓ fixed in latest
CVE-2022-38468 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.29 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.29 3.29 2023-02-14 ✓ fixed in latest
CVE-2020-35942 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.5.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 8.8 < 3.5.0 3.5.0 2020-12-17 ✓ fixed in latest
CVE-2020-35943 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.5.0 Cross-Site Request Forgery (CSRF) Medium 6.5 < 3.5.0 3.5.0 2020-12-17 ✓ fixed in latest
CVE-2019-14314 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.2.11 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.2.11 3.2.11 2019-08-27 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.7 Unknown < 3.1.7 3.1.7 2019-03-02 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.7 Unknown < 3.1.7 3.1.7 2019-02-25 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.6 Unknown < 3.1.6 3.1.6 2019-02-04 ✓ fixed in latest
CVE-2018-7586 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.2.50 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 2.2.50 2.2.50 2018-03-01 ✓ fixed in latest
CVE-2018-1000172 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.2.45 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.2.45 2.2.45 2018-02-14 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.79 Unknown < 2.1.79 2.1.79 2017-02-17 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.60 Unknown < 2.1.60 2.1.60 2016-11-28 ✓ fixed in latest
CVE-2016-10889 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 2.1.57 2.1.57 2016-11-15 ✓ fixed in latest
CVE-2016-6565, CVE-2016-10889 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57 Improper Input Validation High 7.5 < 2.1.57 2.1.57 2016-11-15 ✓ fixed in latest
CVE-2015-9228 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.15 Unrestricted Upload of File with Dangerous Type High 8.8 < 2.1.15 2.1.15 2015-12-23 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.9 Unknown < 2.1.9 2.1.9 2015-10-07 ✓ fixed in latest
CVE-2015-9229 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.23 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.1.23 2.1.23 2015-09-14 ✓ fixed in latest
CVE-2015-9537 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.1.10 2.1.10 2015-08-31 ✓ fixed in latest
CVE-2015-9538 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.15 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 2.1.15 2.1.15 2015-08-28 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.9 Unknown < 2.1.9 2.1.9 2015-08-28 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.66 Unknown < 2.0.66 2.0.66 2015-05-15 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.7 Unknown < 2.0.7 2.0.7 2015-05-15 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.8 Unknown < 1.9.8 1.9.8 2015-05-15 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.0 Unknown < 2.0.0 2.0.0 2015-05-15 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.0 Unknown < 2.0.0 2.0.0 2015-05-15 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.1 Unknown < 1.9.1 1.9.1 2015-05-15 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.8.4 Unknown < 1.8.4 1.8.4 2015-05-15 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.7.4 Unknown < 1.7.4 1.7.4 2015-05-15 ✓ fixed in latest
CVE-2015-1784, CVE-2015-1785 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.77.3 Unrestricted Upload of File with Dangerous Type High 8.8 < 2.0.77.3 2.0.77.3 2015-03-25 ✓ fixed in latest
CVE-2015-1785 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.77.3 Cross-Site Request Forgery (CSRF) Medium 6.5 < 2.0.77.3 2.0.77.3 2015-03-25 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.66 Unknown < 2.0.66 2.0.66 2014-05-20 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.1 Unknown < 2.0.1 2.0.1 2014-02-19 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.7 Unknown < 2.0.7 2.0.7 2014-02-18 ✓ fixed in latest
CVE-2013-3684 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.13 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 1.9.13 1.9.13 2013-06-12 ✓ fixed in latest
CVE-2013-0291 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] >= 1.9.10 - <= 1.9.11 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 1.9.10–2.0.0 2.0.0 2013-02-14 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.11 Unknown < 1.9.11 1.9.11 2013-01-08 ✓ fixed in latest
CVE-2012-3414 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 1.9.7 1.9.7 2012-06-14 ✓ fixed in latest
CVE-2010-1186 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 1.5.2 1.5.2 2010-04-06 ✓ fixed in latest
CVE-2008-7175 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] <= 0.96 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 0.96 0.96 2008-06-07 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.59.5 3.59.5 0000-00-00 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.12 Medium 6.4 < 3.59.12 3.59.12 0000-00-00 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.5 Unknown < 4.0.5 4.0.5 0000-00-00 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.7 Unknown < 3.1.7 3.1.7 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.1.6 Unknown < 3.1.6 3.1.6 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.79 Unknown < 2.1.79 2.1.79 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.9 Unknown < 2.1.9 2.1.9 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.0 Unknown < 2.0.0 2.0.0 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.7.4 Unknown < 1.7.4 1.7.4 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.8 Unknown < 1.9.8 1.9.8 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.8.4 Unknown < 1.8.4 1.8.4 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 1.9.1 Unknown < 1.9.1 1.9.1 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.7 Unknown < 2.0.7 2.0.7 ✓ fixed in latest
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.0.66 Unknown < 2.0.66 2.0.66 ✓ fixed in latest
NextGEN Gallery < 2.0.66 - Arbitrary File Upload Unknown < 2.0.66 2.0.66 ✓ fixed in latest
NextGEN Gallery 2.0.0 - Directory Traversal Unknown < 2.0.7 2.0.7 ✓ fixed in latest
NextGEN Gallery - swfupload.swf Cross-Site Scripting (XSS) Unknown < 1.9.8 1.9.8 ✓ fixed in latest
NextGEN Gallery 1.9.5 - gallerypath Parameter Stored XSS Unknown < 2.0.0 2.0.0 ✓ fixed in latest
NextGEN Gallery <= 1.9.0 - Multiple Cross-Site Scripting (XSS) Unknown < 1.9.1 1.9.1 ✓ fixed in latest
NextGEN Gallery <= 1.8.3 - XXS & CSRF Unknown < 1.8.4 1.8.4 ✓ fixed in latest
NextGEN Gallery <= 1.7.3 - xml/ajax.php Path Disclosure Unknown < 1.7.4 1.7.4 ✓ fixed in latest
NextGEN Gallery < 2.1.9 - Authenticated Path Traversal Unknown < 2.1.9 2.1.9 ✓ fixed in latest
NextGEN Gallery < 2.1.79 - Unauthenticated SQL Injection Unknown < 2.1.79 2.1.79 ✓ fixed in latest
NextGen Gallery <= 3.1.5 - Authenticated PHP Object Injection Unknown < 3.1.6 3.1.6 ✓ fixed in latest
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update Unknown < 3.1.7 3.1.7 ✓ fixed in latest
CVE-2024-5020 Multiple Plugins - Contributor+ DOM-Based Stored XSS via FancyBox JavaScript Library Unknown < 3.59.5 3.59.5 ✓ fixed in latest
CVE-2024-5878 Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library Unknown < 3.59.5 3.59.5 ✓ fixed in latest
CVE-2025-2537 Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library Unknown < 3.59.12 3.59.12 ✓ fixed in latest
CVE-2026-1463 NextGEN Gallery < 4.0.5 - Author+ Local File Inclusion Unknown < 4.0.5 4.0.5 ✓ fixed in latest

How to fix it

Keep Nextgen Gallery updated — 4.2.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.