Impact
Unauthenticated Cross Site Scripting exists in the NextGEN Gallery WordPress plugin versions 4.2.3 and earlier, allowing an attacker to inject arbitrary scripts into the plugin’s output when triggered by a victim browsing the site. This flaw relies on the absence of proper input validation and escaping, matching the definition of CWE‑79. The resulting script execution is performed within the victim’s browser context, which can lead to malicious actions such as session hijacking, defacement, or phishing attempts. The impact is confined to clients who view or interact with the compromised gallery, but it can affect many users visiting the affected site.
Affected Systems
The vulnerability is present in the WordPress plugin NextGEN Gallery by Syed Balkhi for all release versions up to and including 4.2.3. Sites that have installed this plugin and have not upgraded to 4.2.4 or later are potentially exposed. The flaw is specific to the WordPress platform and the gallery component, not to other plugins or core WordPress code.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for a web-based exploit. EPSS data is not available, so the current assessable likelihood of exploitation cannot be quantified, but the absence of a KEV listing suggests no confirmed exploits are in widespread use. Attackers can embed the malicious payload through publicly accessible gallery pages or forms without needing authentication, making the attack vector practical for anonymous threat actors. A successful exploitation would only require a victim to visit the targeted gallery page, making the vulnerability broadly exploitable.
OpenCVE Enrichment