CVE-2020-35943: CSRF
Published Feb 9, 2021
·Updated
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Affected Software
1 affected component
Imagely Nextgen Gallery Wordpress<3.5.0
Event History
Feb 9, 2021
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
Description
Frequently Asked Questions
1
What is CVE-2020-35943?
CVE-2020-35943 is a Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before version 3.5.0 for WordPress that allows File Upload.
2
What is the severity of CVE-2020-35943?
The severity of CVE-2020-35943 is medium with a CVSS score of 6.5.
3
How does CVE-2020-35943 affect WordPress?
CVE-2020-35943 affects WordPress through the NextGEN Gallery plugin before version 3.5.0.
4
How can the CSRF protection be bypassed in CVE-2020-35943?
The CSRF protection in CVE-2020-35943 can be bypassed by not including a nonce parameter.
5
Is there a fix available for CVE-2020-35943?
Yes, a fix is available for CVE-2020-35943. Users should update to version 3.5.0 or later of the NextGEN Gallery plugin for WordPress.