Access violation vulnerability in WordPress Gallery Plugin – NextGEN Gallery 3.38

The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress has a security vulnerability in versions up to 3.38. If someone with administrator-level access were to use the ‘Select View’ feature in the plugin’s developer tools, they could include and execute files on the server. This could be used to get access to sensitive data, bypass access controls, or even execute code. This is possible because the plugin allows images and other “safe” file types to be uploaded and included.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.