PT-2026-99534 · WordPress · Event Gallery
CVE-2026-97164
·
Published
2026-09-27
·
Updated
2026-09-29
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Event Gallery versions prior to 6.5.0
Description
An authenticated user can perform arbitrary path deletion through the
clear cache task. By manipulating the images parameter within the cache.process task, it is possible to recursively delete any directories that the web server has authorization to write to.Recommendations
Update to version 6.5.0 or later.
As a temporary mitigation, restrict access to the
cache.process task to prevent unauthorized directory deletion.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Event Gallery