CVE-2015-5682: Powerplay Gallery Project Powerplay Gallery

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.

Affected products

Published 2017-05-23. Last modified 2026-06-17.