Impact
The plugin contains a flaw that bypasses file‑extension validation when extracting files from an uploaded ZIP archive. A variable reused as a loop counter causes the check to always succeed, allowing an authenticated user with gallery‑management rights to write arbitrary files into a web‑accessible directory. If the host executes files in that directory, the attacker can run arbitrary code, achieving full compromise of the server and its data.
Affected Systems
The vulnerability applies to the WordPress Photo Gallery, Sliders, Proofing and Themes plugin prior to version 4.5.0. All earlier releases expose the flawed ZIP‑import functionality.
Risk and Exploitability
The flaw can be exploited by users who have been granted the gallery‑management privilege, an access level typically granted by an administrator. Although no EPSS score is published, the impact score is effectively high due to the ability to execute code on the web server. The vulnerability is not listed in CISA’s KEV catalog; however, the lack of a mitigation is concerning for sites running affected plugin versions.
OpenCVE Enrichment