CVE-2020-35942: XSS
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35942?
CVE-2020-35942 is a Cross-Site Request Forgery (CSRF) vulnerability in the NextGEN Gallery plugin before version 3.5.0 for WordPress, which allows File Upload and Local File Inclusion via settings modification, leading to Remote Code Execution and XSS.
How can the NextGEN Gallery plugin be affected by CVE-2020-35942?
The NextGEN Gallery plugin before version 3.5.0 for WordPress is affected by CVE-2020-35942.
How severe is CVE-2020-35942?
CVE-2020-35942 has a severity rating of 8.8 (high).
How can I fix CVE-2020-35942?
To fix CVE-2020-35942, update the NextGEN Gallery plugin to version 3.5.0 or newer. Ensure that you include a nonce parameter to bypass CSRF protection.
Are there any references for CVE-2020-35942?
Yes, you can find more information about CVE-2020-35942 and its patches on the Wordfence blog: https://www.wordfence.com/blog/2021/02/severe-vulnerabilities-patched-in-nextgen-gallery-affect-over-800000-wordpress-sites/