CVE-2026-81650: NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that execute them, run arbitrary code.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an account that has been granted NextGEN Gallery's gallery-management capability by an administrator. It is not described as exploitable by unauthenticated visitors or by users without that capability.
What conditions are required for arbitrary code execution?
The attacker must be able to upload a ZIP archive through the affected import functionality, which can write arbitrary extracted files into a web-accessible directory. Code execution depends on the hosting environment executing the uploaded file type.
Are installations on version 4.5.0 affected?
The issue affects versions before 4.5.0. Version 4.5.0 is not identified as affected by the provided information.