Access violation vulnerability in Assistant for NextGEN Gallery 1.0.9

A plugin called “Assistant for NextGEN Gallery” in WordPress has a security issue where it does not properly check the file path in a certain part of the plugin. This means that anyone, without being logged in, can delete important folders on the website’s server. This can lead to the website being completely unavailable.

Detected in:

Assistant for NextGEN Gallery open vulnerable versions: >= * <= 1.0.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.