WordPress Plugin Vulnerabilities
NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import
Description
The plugin does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that execute them, run arbitrary code.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Alihan Şahin
Submitter
Alihan Şahin
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-18 (about 2 days ago)
Added
2026-09-18 (about 1 day ago)
Last Updated
2026-09-18 (about 1 day ago)