Input validation vulnerability in NextGEN Gallery Sell Photo 1.0.4

The NextGEN Gallery Sell Photo plugin for WordPress has a security issue in versions up to and including 1.0.4. Attackers who are authenticated can inject web scripts into pages, which will execute whenever someone visits those pages. The problem is caused by the Button Text/Image field on the settings page not having enough security measures to protect against this type of attack.

Detected in:

NextGEN Gallery Sell Photo open vulnerable versions: >= * <= 1.0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.