CSRF Vulnerability in NextGEN Gallery Plugin for WordPress
CVE-2020-35942
8.8HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability in the NextGEN Gallery plugin before version 3.5.0 for WordPress exposes sites to security risks by allowing attackers to modify settings without proper nonce validation. This lack of adequate CSRF protection can lead to unauthorized file uploads and local file inclusion, creating avenues for Remote Code Execution (RCE) and Cross-Site Scripting (XSS) attacks. Consequently, users are advised to update to the latest version to mitigate these risks and maintain site integrity.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved