VDB-ID: 111 Title: Persistent XSS in NextCellent Gallery 1.9.13 WordPress plugin Vulnerability Date: 2014-03-20 Download: http://wpgetready.com/nextcellent-gallery/ Vendor: Nextcellent Notified: 2014-03-20 Vendor Contact: http://wpgetready.uservoice.com Description: NextCellent Gallery provides a powerful engine for uploading and managing galleries of images, with the ability to batch upload, import meta data, add/delete/rearrange/sort images, edit thumbnails, group galleries into albums, and more. It also provides two front-end display styles (slideshows and thumbnail galleries), both of which come with a wide array of options for controlling size, style, timing, transitions, controls, lightbox effects, and more. Vulnerability: The user supplied data for the Alt & Title Text field isn't escaped before being printed out in the value field: Vulnerability from nextcellent-gallery-nextgen-legacy/admin/manage-images.php lines: 503