CVE-2025-13641: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13641 is a Local File Inclusion (LFI) vulnerability in the NextGEN Gallery WordPress plugin (Photo Gallery, Sliders, Proofing and Themes) affecting all versions up to and including 3.59.12. The flaw resides in the template shortcode parameter, which lacks sufficient path validation, allowing absolute paths to be supplied. Authenticated attackers with Contributor-level access or higher can exploit this to include and execute arbitrary PHP files on the server, bypassing web server restrictions such as .htaccess. It was published on December 18, 2025, and carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). Specifically, the LegacyTemplateLocator.php component fails to restrict the template shortcode parameter to a safe directory, permitting absolute filesystem paths to be passed directly into PHP's file inclusion logic (ENISA EUVD). An attacker crafts a WordPress post or page containing a NextGEN Gallery shortcode with a malicious template value pointing to an arbitrary PHP file already present on the server. The fix was applied in the plugin's LegacyTemplateLocator.php (changeset 3415575 on the WordPress plugin repository) (WordPress Trac).

Impact

Successful exploitation allows an authenticated attacker to include and execute arbitrary PHP files within the WordPress process context, leading to full confidentiality, integrity, and availability compromise (all rated High in the CVSS vector). An attacker can exfiltrate sensitive data (database credentials, WordPress secret keys, user data), modify site content, or establish persistent backdoors. If the target environment also permits file uploads (e.g., via the media library or another plugin), the LFI can be chained into full Remote Code Execution, potentially enabling lateral movement to the underlying server or hosted infrastructure (Wordfence, ENISA EUVD).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA did reference it in its weekly vulnerability bulletin for the week of December 15, 2025 (CISA Bulletin). The EPSS score is approximately 0.087%, indicating a currently low probability of exploitation in the near term. Exploitation requires at minimum Contributor-level WordPress authentication, which limits the attack surface compared to unauthenticated vulnerabilities, but is still a realistic threat on sites with open contributor registration.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running NextGEN Gallery ≤ 3.59.12 using tools like WPScan (wpscan --url https://target.com --enumerate p) or by checking the plugin's readme.txt at https://target.com/wp-content/plugins/nextgen-gallery/readme.txt.
  2. Obtain Contributor Access: Register or compromise a Contributor-level (or higher) WordPress account on the target site.
  3. Identify a target PHP file: Locate a PHP file on the server that can be leveraged — for example, a previously uploaded image file containing embedded PHP code (e.g., via WordPress media upload), or a known PHP file with exploitable content.
  4. Craft the malicious shortcode: Create or edit a post/page and insert a NextGEN Gallery shortcode with the template parameter set to an absolute path of the target PHP file, e.g., [ngg_images template="/var/www/html/wp-content/uploads/2025/12/shell.php"].
  5. Trigger execution: Publish or preview the post/page. The plugin's LegacyTemplateLocator.php resolves the absolute path without restriction and PHP includes the specified file, executing its contents in the WordPress context.
  6. Achieve objective: If the included file is a web shell or reverse shell payload, the attacker gains command execution on the server, enabling data exfiltration, persistence, or lateral movement (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing POST or GET requests to pages/posts containing NextGEN Gallery shortcodes with absolute path values in the template parameter (e.g., template=%2Fvar%2Fwww%2F...); PHP error logs referencing unexpected file inclusions from outside the plugin's template directory.
  • File System: Presence of PHP files with web shell content in the WordPress uploads directory (wp-content/uploads/) or other writable directories; unexpected modification timestamps on PHP files in the NextGEN Gallery plugin directory.
  • Process: Unusual child processes spawned by the web server process (e.g., Apache/Nginx/PHP-FPM) such as bash, curl, wget, or python; outbound network connections from the web server to external IPs.
  • Network: Outbound connections from the web server to unknown external hosts on non-standard ports, potentially indicating reverse shell activity or data exfiltration.

Mitigation and workarounds

The primary remediation is to update the NextGEN Gallery plugin to a version beyond 3.59.12, which includes the patch applied in changeset 3415575 to LegacyTemplateLocator.php (WordPress Trac). If immediate patching is not possible, restrict Contributor-level and above role assignments to only fully trusted users, and disable the NextGEN Gallery plugin until the update can be applied. Additionally, implement a Web Application Firewall (WAF) rule to block shortcode parameters containing absolute path patterns, and audit the WordPress installation for any suspicious files in writable directories (Wordfence).

Community reactions

Wordfence, which discovered and reported the vulnerability, published it in their weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026 (Wordfence Blog). Sucuri included it in their December 2025 vulnerability patch roundup, highlighting the LFI risk to WordPress site operators (Sucuri Blog). The Hacker Wire published a dedicated article noting the critical code execution risk unlocked by Contributor-level access (The Hacker Wire). Community reaction on social media (Mastodon, Bluesky) was largely informational, with security accounts flagging the advisory for WordPress administrators.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management