CVE-2024-39627: WordPress Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely NextGEN Gallery allows Stored XSS.This issue affects NextGEN Gallery: from n/a through 3.59.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39627?
CVE-2024-39627 is classified as a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2024-39627?
To remediate CVE-2024-39627, update your NextGEN Gallery plugin to version 3.59.4 or later.
What is the impact of CVE-2024-39627?
The impact of CVE-2024-39627 includes the possibility of unauthorized script execution in the context of a user's browser, leading to potential data theft or account compromise.
Is CVE-2024-39627 present in all versions of NextGEN Gallery?
CVE-2024-39627 affects all versions of NextGEN Gallery from an unspecified point up to and including version 3.59.3.
Who is affected by CVE-2024-39627?
Users of the NextGEN Gallery plugin for WordPress are at risk if they are running versions prior to 3.59.4.