In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.
| Software | From | Fixed in |
|---|---|---|
| imagely / nextgen_gallery | 2.1.15 | 2.1.15.x |