Executive brief
Apptha Slider Gallery, a WordPress plugin used for creating image slideshows, contains a security flaw that allows unauthorized individuals to access private files. By sending a specially crafted web request, an attacker can bypass security restrictions to download sensitive system files, such as configuration files containing database credentials. This could lead to a full compromise of the website's data and underlying server.
Technical details
A path traversal vulnerability exists in Apptha Slider Gallery 1.0 within the 'asgallDownload.php' component. The issue stems from insufficient sanitization of the 'imgname' parameter, which allows unauthenticated remote attackers to use directory traversal sequences (e.g., '../') to escape the intended directory. By exploiting this, an attacker can read and download arbitrary files from the server, including sensitive WordPress configuration files like 'wp-config.php'. The vulnerability is exploitable via simple GET requests and does not require any user interaction or authentication.
Affected products
- Apptha Slider Gallery 1.0
Timeline
- 2017-03-09: disclosed: Initial exploit published on Exploit-DB
- 2026-06-09: advisory: CVE published and enriched by VulnCheck