CVE-2015-5682: Powerplay Gallery Project Powerplay Gallery
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.
Affected products
- Powerplay Gallery Project Powerplay Gallery: version 3.3 only
Published 2017-05-23. Last modified 2026-06-17.