cleantalk
Vulnerabilities and Security Researches

WordPress Gallery Plugin – NextGEN Gallery, CVE-2020-35943

CVE, Research URL

CVE-2020-35943

Published on
Feb 09, 2021
Research Description
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Affected versions
Min -, max 3.5.0.
Status
vulnerable