CVE-2014-3123
Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & Title Text" field.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0024 (0.2%)
Percentil: 47.6%
EPSS: 2026-05-06
Afecta
wpgetready:nextcellent_galleryDescripción técnica
Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & Title Text" field.
Publicada: 8/5/2014, 14:29:15
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://secunia.com/advisories/58031
- http://www.securityfocus.com/bid/67085
- http://www.vapid.dhs.org/advisories/wordpress/plugins/nextCellent-gallery-1.9.13
- https://wordpress.org/plugins/nextcellent-gallery-nextgen-legacy/changelog
- http://secunia.com/advisories/58031
- http://www.securityfocus.com/bid/67085
- http://www.vapid.dhs.org/advisories/wordpress/plugins/nextCellent-gallery-1.9.13
- https://wordpress.org/plugins/nextcellent-gallery-nextgen-legacy/changelog