WordPress Gallery Plugin – NextGEN Gallery

NextGEN Gallery is a WordPress gallery plugin that has been the industry standard since 2007, with over 1.5 million new downloads per year. It offers a complete WordPress gallery management system on the back end, with the ability to batch upload photos, import meta data, and more. On the front end, it provides various gallery and album styles with a wide array of options for controlling size, style, timing, transitions, controls, lightbox effects, and more. The plugin now also has full support for the Gutenberg block editor.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.59

    Fixed

    The NextGEN Gallery plugin for WordPress, which is used to create galleries on websites, has a security flaw that could allow unauthorized users to access sensitive information. This vulnerability af...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.37

    Fixed

    The NextGEN Gallery plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This means that in versions up to and including 3.37, attackers can trick a site administ...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.38

    Fixed

    The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is a vulnerable piece of software. All versions up to, and including, 3.38 have a security issue that allows attackers with admin...

    Read More
  • Access violation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.38

    Fixed

    The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress has a security vulnerability in versions up to 3.38. If someone with administrator-level access were to use the 'Select View' fea...

    Read More
  • Information leakage vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.37

    Fixed

    The NextGEN Gallery plugin for WordPress has a security vulnerability that could allow attackers with administrator-level privileges to read and delete any file. This vulnerability is present in vers...

    Read More
  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.1.56

    Fixed

    If you are using the Imagely NextGen Gallery plugin for Wordpress

    Read More
  • Access violation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.0

    Fixed

    The NextGen Gallery plugin is a tool created for WordPress that has a security vulnerability. This vulnerability affects versions up to and including 2.0, and it allows people to access files on the ...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.2.11

    Fixed

    The Imagely NextGEN Gallery plugin for WordPress has a security flaw that could let a remote attacker use special commands to run any type of code on the system. This flaw affects versions of the plug...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.1.56

    Fixed

    The WordPress plugin called Nextgen Gallery

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.28

    Fixed

    The NextGEN Gallery plugin for WordPress is not secure in versions up to 3.28. This means that attackers can use a special type of attack

    Read More
  • Output validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.1.5

    Fixed

    The NextGen Gallery plugin for WordPress has a security vulnerability in versions 3.1.5 and earlier. If someone with malicious intent can access the plugin, they can use the "sortorder" parameter to ...

    Read More
  • Access violation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.2.46

    Fixed

    In the WordPress plugin

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.1.10

    Fixed

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.1.77

    Fixed

    The NextGen Gallery plugin for WordPress has a security vulnerability. This vulnerability can be exploited by unauthenticated attackers. If they gain access, they can get sensitive information from t...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.1.9

    Fixed

    The plugin NextGEN Gallery

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.2.44

    Fixed

    The Imagely NextGEN Gallery program

    Read More
  • Access violation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.1.7

    Fixed

    The NextGen Gallery plugin for WordPress has a security vulnerability that affects versions up to and including 2.1.7. An authenticated attacker can use a specific action called 'browse_folder' and a...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 1.9.7

    Fixed

    The NextGen Gallery plugin for WordPress is vulnerable to a type of cyber attack known as Reflected Cross-Site Scripting. This type of attack occurs when a hacker is able to embed malicious code into...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.0.65

    Fixed

    The NextGen Gallery plugin for WordPress is vulnerable to a security problem in versions up to and including 2.0.65. This issue could allow someone with the ability to upload files to exploit the web...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.0.77.3

    Fixed

    The nextgen-galery WordPress plugin

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 1.9.12

    Fixed

    vulnerability

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.4.7

    Fixed

    A security flaw in the NextGEN Gallery plugin version 3.5.0 or earlier for WordPress allowed attackers to upload files to websites using the plugin. The protection against this type of attack was not ...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.1.10

    Fixed

    The NextGEN Gallery plugin is a plugin for WordPress websites that was vulnerable to a problem called Directory Traversal before version 2.1.15. This issue allowed someone to access files and informat...

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 1.5.2

    Fixed

    The NextGEN Gallery plugin for WordPress had an issue with its xml/media-rss.php file that allowed people from across the internet to add malicious code to it. This code could have been in the form of...

    Read More
  • Access violation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 1.9.10

    Fixed

    The NextGEN Gallery Plugin for WordPress

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.4.7

    Fixed

    The NextGEN Gallery plugin for WordPress versions before 3.5.0 had an issue that could allow someone to upload a file to your website

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.0.77.3

    Fixed

    In the nextgen-galery wordpress plugin before version 2.0.77.3

    Read More
  • Input validation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 2.1.15

    Fixed

    In the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress

    Read More
  • Input validation vulnerability in SWFUpload (40 plugins affected)

    Fixed

    Cross-site scripting (XSS) is a type of vulnerability that allows attackers to inject malicious code into webpages. In the case of SWFUpload 2.2.0.1 and earlier, WordPress before 3.3.2, TinyMCE Image...

    Read More
  • Access violation vulnerability in Freemius SDK (134 components affected)

    Fixed

    The Freemius SDK is a plugin used in WordPress websites. A security vulnerability was discovered in versions up to 2.2.3 which could allow users with subscriber-level permissions to change settings an...

    Read More