CVE-2026-32537
WordPress Visual Portfolio, Photo Gallery & Post Grid plugin <= 3.5.1 - Local File Inclusion vulnerability
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Visual Portfolio, Photo Gallery & Post Grid visual-portfolio allows PHP Local File Inclusion.This issue affects Visual Portfolio, Photo Gallery & Post Grid: from n/a through <= 3.5.1.
| CWE | CWE-98 |
| Vendor | nk |
| Product | visual portfolio, photo gallery & post grid |
| Published | Mar 25, 2026 |
| Last Updated | Mar 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for nk visual portfolio, photo gallery & post grid
Be the first to know when new high vulnerabilities affecting nk visual portfolio, photo gallery & post grid are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
nK / Visual Portfolio, Photo Gallery & Post Grid
n/a โค <= 3.5.1
References
Credits
Nguyen Ba Khanh | Patchstack Bug Bounty Program