Description
The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to delete arbitrary directories on the server, which can cause a complete loss of availability.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
*
Timeline
2025-08-14: | Disclosed |
Credits
Youcef Hamdani
References
www.wordfence.com/...-a1f8-4a5c-8d81-a83fda4b0af3?source=cve
plugins.trac.wordpress.org/...ery/trunk/nextgenassistant.php
wordpress.org/plugins/assistant-for-nextgen-gallery/