CVE · High

CVE-2025-13641 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13641 Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.0 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 8.8 < 4.0.0 4.0.0 2025-12-17

CVE-2025-13641

The NextGEN Gallery plugin for WordPress contains a flaw that enables attackers with Contributor-level access or higher to inject and run malicious PHP scripts on the server by manipulating the 'template' parameter within the shortcode. This vulnerability arises from inadequate validation of path inputs, allowing absolute paths to be specified. As a result, sensitive information may be exposed, and potentially even remote code execution can occur if paired with file upload capabilities.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.