CVE-2026-28141: WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/NextGEN Galleryto a version that resolves this vulnerability.Fixed in 4.2.4 - Compensating control
After upgrading NextGEN Gallery, review pages/forms that may have been affected by Cross Site Scripting (XSS) and ensure any malicious input is removed/mitigated as appropriate.