WordPress Plugin Vulnerabilities

NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import

Description

The plugin does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that execute them, run arbitrary code.

Proof of Concept

Affects Plugins

Fixed in 4.5.0

References

Miscellaneous

Original Researcher
Alihan Şahin
Submitter
Alihan Şahin
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-18 (about 2 days ago)
Added
2026-09-18 (about 1 day ago)
Last Updated
2026-09-18 (about 1 day ago)

Other