CVE-2015-1784

HIGH

NextGEN Gallery < 2.0.77.3 - Unauthenticated Arbitrary File Upload and Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0155
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
imagely/nextgen_gallery < 2.0.77.3
Published Jul 07, 2022
Tracked Since Feb 18, 2026