CVE-2026-81650

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator to write arbitrary files into a web-accessible directory and, on hosts that execute them, run arbitrary code.

  • Published Sep 20, 2026
  • CVSS 7.2 high
  • 0.5% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-81650 at the National Vulnerability Database