Vulnerability Description
The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to delete arbitrary directories on the server, which can cause a complete loss of availability.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://plugins.trac.wordpress.org/browser/assistant-for-nextgen-gallery/trunk/ne
- https://wordpress.org/plugins/assistant-for-nextgen-gallery/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/07ebb176-a1f8-4a5c-8d8
FAQ
What is CVE-2025-7641?
CVE-2025-7641 is a vulnerability with a CVSS score of 7.5 (HIGH). The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpo...
How severe is CVE-2025-7641?
CVE-2025-7641 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-7641?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.