Local File Inclusion Vulnerability in NextGEN Gallery Plugin for WordPress
CVE-2026-1463
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 March 2026
What is CVE-2026-1463?
The NextGEN Gallery plugin for WordPress has a Local File Inclusion vulnerability that allows authenticated attackers with Author-level access and above to exploit the 'template' parameter in gallery shortcodes. This vulnerability enables them to include and execute arbitrary .php files stored on the server, leading to potential bypass of access controls, exposure of sensitive data, or execution of malicious PHP code. Users of versions 4.0.3 and earlier should take immediate action to mitigate this risk and secure their installations.
Affected Version(s)
Photo Gallery, Sliders, Proofing and Themes β NextGEN Gallery 0 <= 4.0.4