A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-09T17:49:27

Updated: 2024-08-04T17:16:13.390Z

Reserved: 2021-01-01T00:00:00

Link: CVE-2020-35943

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-02-09T18:15:45.370

Modified: 2021-02-12T15:23:34.010

Link: CVE-2020-35943

cve-icon Redhat

No data.