Home

Description

The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to delete arbitrary directories on the server, which can cause a complete loss of availability.

PUBLISHED Reserved 2025-07-14 | Published 2025-08-15 | Updated 2025-08-15 | Assigner Wordfence




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

*
affected

Timeline

2025-08-14:Disclosed

Credits

Youcef Hamdani finder

References

www.wordfence.com/...-a1f8-4a5c-8d81-a83fda4b0af3?source=cve

plugins.trac.wordpress.org/...ery/trunk/nextgenassistant.php

wordpress.org/plugins/assistant-for-nextgen-gallery/

cve.org (CVE-2025-7641)

nvd.nist.gov (CVE-2025-7641)

Download JSON