File Upload and CSRF Vulnerabilities in NextGen Gallery Plugin for WordPress
CVE-2015-1784

8.8HIGH

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
7 July 2022

What is CVE-2015-1784?

The NextGen Gallery plugin for WordPress, prior to version 2.0.77.3, contains critical vulnerabilities that compromise web application security. The flaws are primarily due to improper validation of user-uploaded files and inadequate security measures against unwanted HTTP requests. These vulnerabilities could be exploited by attackers to potentially gain unauthorized access to the application and its data. Users are advised to restrict the plugin version and apply necessary updates to avoid these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

nextgen-gallery nextgen-gallery 2.0.77.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.