CyberRota Analysis
AI-GeneratedThe Photo Gallery, Sliders, Proofing, and WordPress plugin versions prior to 4.5.0 have a vulnerability that allows users with gallery-management permissions to upload files with unchecked extensions, leading to the potential execution of arbitrary code on affected servers. This flaw arises from improper validation during file extraction, enabling unauthorized file writes to web-accessible directories. WordPress site administrators and developers using this plugin should prioritize updates to mitigate the risk of exploitation.
Original NVD Description
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that execute them, run arbitrary code.