NextGen Cu3er Gallery <= 0.1 - Multiple Full Path Disclosures
mediumThe NextGen Cu3er Gallery plugin for WordPress is vulnerable to Multiple Full Path Disclosures in versions up to, and including, 0.1 via the xml_made_by_me.php file. This can allow unauthenticated attackers to disclose the full path to a resource on the web server.
- CVSS:
- 5.3
- Affected:
- up to 0.1
- Fix:
- No patched version reported
- Disclosed:
- May 15, 2015