What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
Explanation of Vulnerability in Simple Terms
The NextGen GalleryView WordPress plugin through version 0.5.5 contains a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in the browsers of site visitors. The vulnerability requires user interaction—typically a victim clicking a crafted link—and can affect other users and site functionality. Update the plugin immediately to a version newer than 0.5.5.
What an attacker can do
Inject malicious scripts that run in visitors' browsers, stealing cookies, session tokens, or performing actions on their behalf.
Potential impact on your site
Visitors' accounts and data are at risk; attackers can deface content, steal credentials, or redirect users to malicious sites.
Conditions required to exploit
No authentication required. Victim must click a malicious link or visit a page containing the attacker's payload.
Key dates
External resources
Related vulnerabilities