VYPR
Unrated severityNVD Advisory· Published Sep 20, 2026

CVE-2026-81650

CVE-2026-81650

Description

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that execute them, run arbitrary code.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.