WordPress NextGEN Gallery version 2.1.15 suffers from cross site scripting and path traversal vulnerabilities.