Lucene search

K
patchstackWordFencePATCHSTACK:6344780F635F3AC0058849F0DAD32CCE
HistoryFeb 08, 2021 - 12:00 a.m.

WordPress NextGen Gallery plugin <= 3.4.7 - Cross-Site Request Forgery (CSRF) leading to XSS and RCE via file upload and LFI

2021-02-0800:00:00
WordFence
patchstack.com
11
wordpress
nextgen gallery
plugin
cross-site request forgery
xss
remote code execution
file upload
local file inclusion
wordfence
update

EPSS

0.001

Percentile

38.5%

Cross-Site Request Forgery (CSRF) leading to XSS and RCE via file upload and LFI found by WordFence in WordPress NextGen Gallery plugin (versions <= 3.4.7).

Solution

           Update the WordPress NextGen Gallery plugin to the latest available version (at least 3.5.0).

EPSS

0.001

Percentile

38.5%

Related for PATCHSTACK:6344780F635F3AC0058849F0DAD32CCE