Critical Security Alert for the WordPress NextGEN Gallery

User avatar
Claude
cheese lizard
Posts: 6241
Joined: 16 Jan 2010, 00:14
Location: Sydney Australia

Critical Security Alert for the WordPress NextGEN Gallery

Post by Claude »

Sucuri has posted a Critical Security Alert for the NextGEN Gallery for WordPress plugin...
...we discovered a severe SQL Injection vulnerability. This vulnerability allows an unauthenticated user to grab data from the victim’s website database, including sensitive user information.
https://blog.sucuri.net/2017/02/sql-inj ... press.html
An updated version has already been released and anyone using this plugin should immediately update their plugin or disable until such time as they can update.

Additional Information is available here:
https://wordpress.org/plugins/nextgen-gallery/
Cheers, Claude.