Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

Vulnerabilities 66Slug nextgen-galleryLatest version 4.2.0WordPress.org →

Minimum safe version

4.0.5

Update to 4.0.5 or later to address 64 fixable vulnerabilities

Latest available4.2.0 Affected up to1.9.11
Medium 6.4
2025-07-03< 3.59.12

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library

N/A
2026-03-17< 4.0.5

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File Inclusion

N/A
2025-07-03< 3.59.12

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript Library

Medium 6.4
2025-05-20< 3.59.5

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via SimpleLightbox JavaScript Library

Medium 6.4
2024-12-04< 3.59.5

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library

Medium 5.9
2024-07-15< 3.59.3

WordPress NextGEN Gallery Plugin < 3.59.3 is vulnerable to Cross Site Scripting (XSS)

N/A
< 2.0.66

NextGEN Gallery &lt;= 2.0.63 - Arbitrary File Upload

N/A
< 2.0.7

NextGEN Gallery 2.0.0 - Directory Traversal

N/A
< 1.9.1

NextGEN Gallery &lt;= 1.9.0 - Multiple Cross-Site Scripting (XSS)

N/A
< 1.8.4

NextGEN Gallery &lt;= 1.8.3 - XXS &amp; CSRF

N/A
< 1.9.8

NextGEN Gallery - swfupload.swf Cross-Site Scripting (XSS)

N/A
< 1.7.4

NextGEN Gallery &lt;= 1.7.3 - xml/ajax.php Path Disclosure

N/A
< 2.0.0

NextGEN Gallery 1.9.5 - gallerypath Parameter Stored XSS

N/A
< 2.1.9

NextGEN Gallery &lt; 2.1.9 - Authenticated Path Traversal

N/A
< 2.1.79

NextGEN Gallery &lt; 2.1.79 - Unauthenticated SQL Injection

N/A
< 3.1.6

NextGen Gallery &lt;= 3.1.5 - Authenticated PHP Object Injection

N/A
2023-07-19< 3.4.7

WordPress NextGEN Gallery Plugin <= 3.3.6 is vulnerable to Cross Site Scripting (XSS)

N/A
2014-02-18< 2.0.7

NextGen Gallery <= 2.0 - Path Traversal

N/A
2014-05-20< 2.0.66

NextGen Gallery <= 2.0.65 - Arbitrary File Upload

N/A
2015-08-28< 2.1.9

NextGen Gallery <= 2.1.7 - Path Traversal

N/A
2017-02-17< 2.1.79

NextGen Gallery <= 2.1.77 - SQL Injection

N/A
2019-02-04< 3.1.6

NextGen Gallery <= 3.1.5 - PHP Object Injection

N/A
2019-02-25< 3.1.7

Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

N/A
< 3.1.7

Freemius Library &lt; 2.2.4 - Subscriber+ Arbitrary Option Update

N/A
2014-02-19< 2.0.1

WordPress NextGEN Gallery Plugin - Directory Traversal

N/A
2013-01-08< 1.9.11

WordPress NextGEN Gallery Plugin - Cross Site Scripting

N/A
2015-05-15< 1.7.4

WordPress NextGEN Gallery Plugin <= 1.7.3 - Full Path Disclosure

N/A
2015-05-15< 1.8.4

WordPress NextGEN Gallery Plugin <= 1.8.3 - Multiple Vulnerabilities

N/A
2015-05-15< 1.9.1

WordPress NextGEN Gallery Plugin <= 1.9.0 - Multiple XSS

N/A
2015-05-15< 2.0.0

WordPress NextGEN Gallery Plugin <= 1.9.5 - Stored XSS

N/A
2015-05-15< 2.0.0

WordPress NextGEN Gallery Plugin <= 1.9.11 - Full Path Disclosure

N/A
2015-05-15< 1.9.8

WordPress NextGEN Gallery Plugin <= 1.9.7 - Cross Site Scripting

N/A
2015-05-15< 2.0.7

WordPress NextGEN Gallery Plugin <= 2.0.0 - Directory Traversal

N/A
2015-05-15< 2.0.66

WordPress NextGEN Gallery Plugin <= 2.0.63 - Arbitrary File Upload

N/A
2015-10-07< 2.1.9

WordPress NextGEN Gallery Plugin <= 2.1.7 - Authenticated Path Traversal

N/A
2016-11-28< 2.1.60

WordPress NextGEN Gallery plugin <= 2.1.59 - Authenticated Remote Code Execution (RCE) Vulnerability

N/A
2019-03-02< 3.1.7

WordPress NextGEN Gallery plugin <= 3.1.6 - Authenticated Option Update vulnerability (Fremius Library security issue)