
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13641 is a Local File Inclusion (LFI) vulnerability in the NextGEN Gallery WordPress plugin (Photo Gallery, Sliders, Proofing and Themes) affecting all versions up to and including 3.59.12. The flaw resides in the template shortcode parameter, which lacks sufficient path validation, allowing absolute paths to be supplied. Authenticated attackers with Contributor-level access or higher can exploit this to include and execute arbitrary PHP files on the server, bypassing web server restrictions such as .htaccess. It was published on December 18, 2025, and carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).
The root cause is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). Specifically, the LegacyTemplateLocator.php component fails to restrict the template shortcode parameter to a safe directory, permitting absolute filesystem paths to be passed directly into PHP's file inclusion logic (ENISA EUVD). An attacker crafts a WordPress post or page containing a NextGEN Gallery shortcode with a malicious template value pointing to an arbitrary PHP file already present on the server. The fix was applied in the plugin's LegacyTemplateLocator.php (changeset 3415575 on the WordPress plugin repository) (WordPress Trac).
Successful exploitation allows an authenticated attacker to include and execute arbitrary PHP files within the WordPress process context, leading to full confidentiality, integrity, and availability compromise (all rated High in the CVSS vector). An attacker can exfiltrate sensitive data (database credentials, WordPress secret keys, user data), modify site content, or establish persistent backdoors. If the target environment also permits file uploads (e.g., via the media library or another plugin), the LFI can be chained into full Remote Code Execution, potentially enabling lateral movement to the underlying server or hosted infrastructure (Wordfence, ENISA EUVD).
As of the disclosure date, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA did reference it in its weekly vulnerability bulletin for the week of December 15, 2025 (CISA Bulletin). The EPSS score is approximately 0.087%, indicating a currently low probability of exploitation in the near term. Exploitation requires at minimum Contributor-level WordPress authentication, which limits the attack surface compared to unauthenticated vulnerabilities, but is still a realistic threat on sites with open contributor registration.
wpscan --url https://target.com --enumerate p) or by checking the plugin's readme.txt at https://target.com/wp-content/plugins/nextgen-gallery/readme.txt.template parameter set to an absolute path of the target PHP file, e.g., [ngg_images template="/var/www/html/wp-content/uploads/2025/12/shell.php"].LegacyTemplateLocator.php resolves the absolute path without restriction and PHP includes the specified file, executing its contents in the WordPress context.template parameter (e.g., template=%2Fvar%2Fwww%2F...); PHP error logs referencing unexpected file inclusions from outside the plugin's template directory.wp-content/uploads/) or other writable directories; unexpected modification timestamps on PHP files in the NextGEN Gallery plugin directory.bash, curl, wget, or python; outbound network connections from the web server to external IPs.The primary remediation is to update the NextGEN Gallery plugin to a version beyond 3.59.12, which includes the patch applied in changeset 3415575 to LegacyTemplateLocator.php (WordPress Trac). If immediate patching is not possible, restrict Contributor-level and above role assignments to only fully trusted users, and disable the NextGEN Gallery plugin until the update can be applied. Additionally, implement a Web Application Firewall (WAF) rule to block shortcode parameters containing absolute path patterns, and audit the WordPress installation for any suspicious files in writable directories (Wordfence).
Wordfence, which discovered and reported the vulnerability, published it in their weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026 (Wordfence Blog). Sucuri included it in their December 2025 vulnerability patch roundup, highlighting the LFI risk to WordPress site operators (Sucuri Blog). The Hacker Wire published a dedicated article noting the critical code execution risk unlocked by Contributor-level access (The Hacker Wire). Community reaction on social media (Mastodon, Bluesky) was largely informational, with security accounts flagging the advisory for WordPress administrators.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."