WordPress Plugin NextGEN Gallery-WordPress Gallery is prone to a cross-site scripting vulnerability and a cross-site request forgery vulnerability. An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, or perform unauthorized actions; other attacks are also possible. WordPress Plugin NextGEN Gallery-WordPress Gallery version 1.8.3 is vulnerable; prior versions may also be affected.
Update to plugin version 1.8.4 or latest
WordPress Plugin Booked-Appointment Booking for WordPress Security Bypass (2.2.5)
WordPress Plugin OptionTree Cross-Site Scripting (2.5.3)
WordPress Plugin Connector for Gravity Forms and Google Sheets Cross-Site Scripting (1.1.0)
Drupal Core 4.6.x Cross-Site Request Forgery (4.6.0 - 4.6.9)
WordPress Plugin Shareaholic-share buttons, related posts, social analytics & more Cross-Site Scripting (220.127.116.11)