Impact
An improper neutralization of input during web page generation allows attackers to inject malicious JavaScript into the search query of the NextGEN Gallery Search plugin. The resulting reflected XSS executes in the browser context of any visitor who follows the crafted link, enabling session hijacking, cookie theft, or site defacement. This issue falls under CWE‑79 and carries a CVSS score of 7.1, indicating a high‑severity vulnerability.
Affected Systems
WordPress sites that use the Koen Schuit NextGEN Gallery Search plugin at any released version up to and including 2.12 are affected. All earlier or equal releases without an update are vulnerable. Site owners should verify the installed plugin version and consider the need for immediate patching.
Risk and Exploitability
With an EPSS score of less than 1 % the likelihood of current exploitation is low, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, the flaw can be triggered remotely by submitting a crafted search string, and no authentication is required. An attacker can deliver the malicious payload via a simple URL, so mitigation should be prioritized to prevent any visitor from executing the injected script.
OpenCVE Enrichment
EUVD