Impact
The Assistant for NextGEN Gallery plugin for WordPress contains an insufficient file path validation flaw in its REST API endpoint /wp-json/nextgenassistant/v1.0.0/control. This flaw allows an unauthenticated attacker to instruct the server to delete arbitrary directories, leading to complete loss of functionality for the affected site. The weakness is a classic directory traversal/validation error (CWE‑22).
Affected Systems
WordPress sites using the Assistant for NextGEN Gallery plugin version 1.0.9 or earlier are susceptible. The vulnerability affects all releases up to and including 1.0.9 and is present in the plugin maintained by 48hmorris.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity with potential for complete loss of availability. The EPSS score of less than 1% suggests that exploitation is currently uncommon, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an unauthenticated HTTP request to the exposed REST endpoint, a path that is inferred from the description because the official documentation does not explicitly state it. Given the nature of the flaw, an attacker does not need privileged credentials, and the impact can be dramatic for a live site.
OpenCVE Enrichment
EUVD