CVE-2026-81650
NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that execute them, run arbitrary code.
| Vendor | unknown |
| Product | photo gallery, sliders, proofing and themes |
| Published | Sep 20, 2026 |
| Last Updated | Sep 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown photo gallery, sliders, proofing and themes
Be the first to know when new high vulnerabilities affecting unknown photo gallery, sliders, proofing and themes are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Unknown / Photo Gallery, Sliders, Proofing and Themes
0 < 4.5.0
References
Credits
Alihan Εahin WPScan