Impact
The vulnerability allows an attacker to delete arbitrary files on the host system where the WordPress Picture Gallery plugin is installed. This weakness, classified as CWE‑22, compromises file integrity and can disrupt service availability, as critical files or configuration data may be removed.
Affected Systems
WordPress sites running the Picture Gallery plugin (videowhisper) version 1.6.5 or earlier.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation currently. The attack vector is not explicitly stated; it is inferred that success requires the attacker to act as a plugin contributor or otherwise gain write access to the plugin directory. The vulnerability is not listed in CISA’s KEV catalog, further indicating limited current exploitation activity.
OpenCVE Enrichment