NextCellent Gallery <= 1.9.35 - Authenticated (Admin+) Cross-Site Scripting
medium
The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
- CVSS:
- 4.8
- Affected:
- up to 1.9.35
- Fix:
- No patched version reported
- Disclosed:
- Jun 6, 2022
CVE-2022-1971 on NVD →
NextCellent Gallery < 1.9.18 - Stored Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & T...
- CVSS:
- 5.5
- Affected:
- up to 1.9.18
- Fixed in:
- 1.9.18
- Disclosed:
- Apr 29, 2014
CVE-2014-3123 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database