NextGen Gallery (WordPress) Update
2625Warning Date
Severity Level
Warning Number
Target Sector
9 February, 2021
● Critical
2021-2432
All
Description:
Wordfence has released security update to address multiple vulnerabilities in the following plugin:
- WordPress Gallery Plugin – NextGEN Galler
- Versions earlier than 3.5.0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Remote code execution
Best practice and Recommendations:
The CERT team encourages users to review Wordfence security advisory and apply the necessary updates: