Unrated severityNVD Advisory· Published May 5, 2021· Updated Aug 3, 2024
NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24293
Description
In the eCommerce module of the NextGEN Gallery Pro WordPress plugin before 3.1.11, there is an action to call get_cart_items via photocrati_ajax , after that the settings[shipping_address][name] is able to inject malicious javascript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<3.1.11+ 1 more
- (no CPE)range: <3.1.11
- (no CPE)range: <3.1.11
Patches
Vulnerability mechanics
References
2- wpscan.com/vulnerability/5e1a4725-3d20-44b0-8a35-bbf4263957f7mitrex_refsource_CONFIRM
- www.imagely.com/wordpress-gallery-plugin/nextgen-pro/changelog/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.