CVE-2018-7586: Path Traversal
Published Mar 1, 2018
·Updated
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress<=2.2.46
Event History
Mar 1, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-7586?
CVE-2018-7586 is a vulnerability in the nextgen-gallery plugin before 2.2.50 for WordPress, where gallery paths are not secured.
2
What software is affected by CVE-2018-7586?
The nextgen-gallery plugin versions up to and including 2.2.46 for WordPress are affected by CVE-2018-7586.
3
How severe is CVE-2018-7586?
CVE-2018-7586 has a severity score of 7.5 (high).
4
How can I fix CVE-2018-7586?
To fix CVE-2018-7586, upgrade to version 2.2.50 or later of the nextgen-gallery plugin.
5
Where can I find more information about CVE-2018-7586?
You can find more information about CVE-2018-7586 on the official WordPress plugin page and the WPScan Vulnerability Database.