WordPress · Nextgen Gallery · CVE-2024-39627
**Name of the Vulnerable Software and Affected Versions**
NextGEN Gallery versions 3.59.3 and earlier
**Description**
The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows for Stored XSS, which can lead to malicious script execution.
**Recommendations**
For versions 3.59.3 and earlier, update the plugin to a patched version immediately. As a temporary workaround, consider restricting access to sensitive areas of the gallery to minimize the risk of exploitation.