CVE-2026-81650: Unknown Photo Gallery, Sliders, Proofing And Themes
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that execute them, run arbitrary code.
Affected products
- Unknown Photo Gallery, Sliders, Proofing And Themes: before 4.5.0 (fixed in 4.5.0)
Published 2026-09-20. Last modified 2026-09-21.