Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shauno NextGEN Gallery Voting nextgen-gallery-voting allows Reflected XSS.This issue affects NextGEN Gallery Voting: from n/a through <= 2.7.6.
Published: 2025-03-26
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

shauno's NextGEN Gallery Voting plugin contains an Improper Neutralization of Input During Web Page Generation vulnerability, allowing attackers to inject arbitrary JavaScript that will be executed in the browser of any user visiting a reflected URL. This reflected Cross Site Scripting flaw is listed as CWE-79 and can be used to steal session cookies, deface pages, or deliver phishing content. The issue exists in all releases up to and including 2.7.6, meaning any site that has not upgraded beyond that version is potentially vulnerable.

Affected Systems

WordPress users who have installed the NextGEN Gallery Voting plugin, particularly versions 2.7.6 or older. The plugin, developed by shauno, is distributed on the WordPress plugin repository and is commonly integrated into galleries on many sites. The vulnerability was reported to affect releases from the earliest to 2.7.6, so any site running the plugin within that range is impacted.

Risk and Exploitability

The CVSS score of 7.1 classifies this flaw as high severity, and the EPSS score indicates a very low probability of exploitation at the present time. The vulnerability is not listed in CISA's KEV catalog, suggesting limited known exploitation. Attackers can exploit it by crafting a malicious URL or form payload that contains script payloads; this payload is reflected back in the plugin's output without proper sanitization. An attacker only requires a user to visit the crafted link for the payload to execute, making it a user agent dependent threat that can facilitate credential theft or site defacement.

Generated by OpenCVE AI on May 1, 2026 at 13:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NextGEN Gallery Voting to the latest release that removes the reflected XSS flaw (any version greater than 2.7.6).
  • If an immediate upgrade is not possible, disable the voting feature or restrict it to authenticated users only to eliminate the vulnerable input path.
  • Configure a Web Application Firewall or similar security rule to block requests containing script tags or other XSS payloads that target the plugin's input parameters.

Generated by OpenCVE AI on May 1, 2026 at 13:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8156 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NextGEN Gallery Voting allows Reflected XSS. This issue affects NextGEN Gallery Voting: from n/a through 2.7.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NextGEN Gallery Voting allows Reflected XSS. This issue affects NextGEN Gallery Voting: from n/a through 2.7.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shauno NextGEN Gallery Voting nextgen-gallery-voting allows Reflected XSS.This issue affects NextGEN Gallery Voting: from n/a through <= 2.7.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 26 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound NextGEN Gallery Voting allows Reflected XSS. This issue affects NextGEN Gallery Voting: from n/a through 2.7.6.
Title WordPress NextGEN Gallery Voting plugin <= 2.7.6 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:49.347Z

Reserved: 2025-03-11T08:08:49.774Z

Link: CVE-2025-28869

cve-icon Vulnrichment

Updated: 2025-03-26T15:55:40.209Z

cve-icon NVD

Status : Deferred

Published: 2025-03-26T15:16:14.617

Modified: 2026-04-23T15:26:28.453

Link: CVE-2025-28869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T13:30:17Z

Weaknesses