WordPress Aeroscroll Gallery Directory Traversal Vulnerability

Vulnerability

A directory traversal vulnerability has been identified in the WordPress Aeroscroll Gallery plugin, specifically in versions through 1.0.12. This vulnerability allows for path traversal, which could enable a malicious actor to access files outside of the intended directory, potentially leading to the exploitation of other weaknesses within the system.

Impact

Exploitation of this vulnerability could allow unauthorized access to files on the server, including sensitive information, which could be used to exploit other vulnerabilities or weaknesses in the system.

Remediation

Users of the WordPress Aeroscroll Gallery plugin are advised to update to a version later than 1.0.12. For those unable to update immediately, Patchstack offers a virtual patch that can be applied to mitigate the vulnerability until an official update is available.

Added: Jun 17, 2025, 4:05 PM
Updated: Jun 17, 2025, 4:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.