Home

Description

Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.

PUBLISHED Reserved 2026-06-08 | Published 2026-06-09 | Updated 2026-06-09 | Assigner VulnCheck




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

3.0
affected

Credits

Ihsan Sencan finder

References

www.exploit-db.com/exploits/41566 (ExploitDB-41566) exploit

www.apptha.com/ (Official Product Homepage) product

www.vulncheck.com/...c-photo-gallery-arbitrary-file-download (VulnCheck Advisory: WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download) third-party-advisory

cve.org (CVE-2017-20250)

nvd.nist.gov (CVE-2017-20250)

Download JSON