Assistant for NextGEN Gallery WordPress Plugin Arbitrary Directory Deletion Vulnerability

Vulnerability

A vulnerability allowing arbitrary directory deletion has been identified in the Assistant for NextGEN Gallery WordPress plugin, in all versions through 1.0.9. This issue arises from inadequate file path validation in the REST endpoint /wp-json/nextgenassistant/v1.0.0/control. As a result, unauthenticated attackers can delete arbitrary directories on the server, leading to a complete loss of availability.

Impact

Exploitation of this vulnerability allows for unauthenticated attackers to delete arbitrary directories on the server, causing a complete loss of availability.

Reproduction

The vulnerability can be reproduced by sending a POST request to the /wp-json/nextgenassistant/v1.0.0/control endpoint. The request must include a destination path that traverses directories, such as '../', which the plugin fails to properly validate. This allows for the deletion of directories outside the intended scope.

Remediation

No known patch is available. It is recommended to uninstall the affected plugin and find a replacement.

Added: Aug 15, 2025, 9:33 AM
Updated: Aug 15, 2025, 9:33 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
0.0
relevance
0.3
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.