Junglewise Threat Intelligence

CVE-2026-81650: NextGEN Gallery arbitrary file upload via ZIP import

CVE-2026-81650 · Severity: high · CVSS 7.2 · Published 2026-09-20

Technologies: Imagely NextGEN Gallery. Vendors: Imagely.

Executive brief

NextGEN Gallery is a WordPress plugin that manages photo galleries on websites. A flaw in the file extraction process allows users with gallery-management privileges to upload malicious files disguised in ZIP archives, potentially executing arbitrary code on the web server.

Technical details

The plugin fails to validate file extensions during ZIP archive extraction due to a loop counter variable reuse, causing the extension check to always pass. An authenticated attacker with gallery-management capability can exploit this to write arbitrary files to web-accessible directories. On servers configured to execute the uploaded files, this enables remote code execution.

Affected products

  • Imagely NextGEN Gallery before 4.5.0

Timeline

  • 2026-09-18: disclosed
  • 2026-09-20: patched: version 4.5.0 released

References

Related threats