CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It affects WordPress.
CVE
CVE-2020-35943
Severity
MEDIUM
CVSS
6.5
EPSS
0.73%
WordPress
Original NVD Description
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)
Related CVEs
Other vulnerabilities affecting the same vendor(s)