Impact
The plugin contains a flaw that bypasses file‑extension validation when extracting files from an uploaded ZIP archive. A variable reused as a loop counter causes the check to always succeed, allowing an authenticated user with gallery‑management rights to write arbitrary files into a web‑accessible directory. If the host executes files in that directory, the attacker can run arbitrary code, achieving full compromise of the server and its data.
Affected Systems
The vulnerability applies to the WordPress Photo Gallery, Sliders, Proofing and Themes plugin prior to version 4.5.0. All earlier releases expose the flawed ZIP‑import functionality.
Risk and Exploitability
The flaw can be exploited by users who have been granted the gallery‑management privilege, an access level typically granted by an administrator. The CVSS score of 7.2 indicates high severity, and the EPSS score of 0.00139 (≈0.14%) indicates a low but nonzero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog; however, the lack of a mitigation is concerning for sites running affected plugin versions.
OpenCVE Enrichment