CVE Database /
CVE-2025-13641
CVE · High
CVE-2025-13641 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-13641
|
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.0 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
High
8.8
|
< 4.0.0
|
4.0.0 |
2025-12-17 |
—
|
CVE-2025-13641
The NextGEN Gallery plugin for WordPress contains a flaw that enables attackers with Contributor-level access or higher to inject and run malicious PHP scripts on the server by manipulating the 'template' parameter within the shortcode. This vulnerability arises from inadequate validation of path inputs, allowing absolute paths to be specified. As a result, sensitive information may be exposed, and potentially even remote code execution can occur if paired with file upload capabilities.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings