Local File Inclusion Vulnerability in NextGEN Gallery Plugin for WordPress
CVE-2026-1463
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 March 2026
What is CVE-2026-1463?
The NextGEN Gallery plugin for WordPress has a Local File Inclusion vulnerability that allows authenticated attackers with Author-level access and above to exploit the 'template' parameter in gallery shortcodes. This vulnerability enables them to include and execute arbitrary .php files stored on the server, leading to potential bypass of access controls, exposure of sensitive data, or execution of malicious PHP code. Users of versions 4.0.3 and earlier should take immediate action to mitigate this risk and secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Photo Gallery, Sliders, Proofing and Themes β NextGEN Gallery * <= 4.0.4