Impact
The vulnerability is an unauthenticated arbitrary file download flaw that allows an attacker to retrieve any file on the server by manipulating the download URL. CWE‑22 categorizes this as a relative path traversal or file inclusion weakness. Because there is no authentication required, an attacker can potentially expose configuration files, credentials, or other sensitive information, leading to a loss of confidentiality and potential compromise of the site.
Affected Systems
WordPress installations running the Syed Balkhi NextGEN Gallery plugin version 4.5.0 or earlier are affected. Updating the plugin to version 4.5.1 or later removes the flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates high risk, and while an EPSS score is not available, the absence of authentication requirements and the nature of the flaw suggest that exploitation is likely. The vulnerability is not listed in the CISA KEV catalog, but its potential for data disclosure warrants immediate attention.
OpenCVE Enrichment