Input validation vulnerability in NGG Smart Image Search 3.2.1

The NGG Smart Image Search plugin for WordPress can be hacked through a vulnerability called Stored Cross-Site Scripting. This happens when the plugin uses the ‘hr_SIS_nextgen_searchbox’ code without properly checking and cleaning the information that users give it. Because of this, someone who has permission to use the plugin can add harmful web scripts to pages and when someone visits those pages, the scripts will run.

Detected in:

NGG Smart Image Search open vulnerable versions: >= * <= 3.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.