CVE-2025-7641: Assistant for NextGEN Gallery <= 1.0.9 - Unauthenticated Arbitrary Directory Deletion
The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to delete arbitrary directories on the server, which can cause a complete loss of availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7641?
CVE-2025-7641 is considered a high severity vulnerability due to its potential for arbitrary directory deletion.
How do I fix CVE-2025-7641?
To fix CVE-2025-7641, update the Assistant for NextGEN Gallery plugin to version 1.0.10 or higher, which addresses the vulnerability.
Which versions are affected by CVE-2025-7641?
CVE-2025-7641 affects all versions of the Assistant for NextGEN Gallery plugin up to and including version 1.0.9.
What can an attacker do exploiting CVE-2025-7641?
An attacker exploiting CVE-2025-7641 can delete arbitrary directories on the server, leading to potential data loss and service disruption.
Is authentication required to exploit CVE-2025-7641?
No, authentication is not required to exploit CVE-2025-7641, making it more critical for affected sites.