Vulnerability record · CVE-2014-9312 · published 28 August 2017
CVE-2014-9312: WordPress Photo Gallery plugin unrestricted file upload
10web · Photo Gallery
Photo Gallery 1.2.5 (10web) contains an unrestricted file upload flaw (CWE-434) that lets a user upload files without proper type or extension validation. Because the plugin is a WordPress component, a successful upload can place executable content on the web server, making this a direct path to remote code execution. The record is thin on technical detail beyond the flaw class and version, but the impact class is severe.
Description
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with public exploit references and very high EPSS, though no KEV listing or confirmed campaign.
What it is
Photo Gallery 1.2.5 (10web) contains an unrestricted file upload flaw (CWE-434) that lets a user upload files without proper type or extension validation. Because the plugin is a WordPress component, a successful upload can place executable content on the web server, making this a direct path to remote code execution. The record is thin on technical detail beyond the flaw class and version, but the impact class is severe.
Impact
An attacker with a low-privileged account can upload arbitrary files, including a web shell, and execute code on the host under the web server's privileges. That yields full compromise of the site's confidentiality, integrity and availability.
Attack surface
Reached over the network through the plugin's upload functionality; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). No authentication bypass is implied, so a valid low-privileged account is needed.
Exploitation
Public exploit code is referenced (Packetstorm shell upload entries) and EPSS is 0.45354 (98.7th percentile), indicating high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaign is recorded here.
What to do
- Update or remove the Photo Gallery plugin; 1.2.5 is the only version named, so treat any unpatched install as vulnerable.
- If patching is not immediately possible, disable the plugin or restrict upload functionality.
- Enforce server-side upload validation and block script execution in upload directories.
- Restrict who can upload media and review low-privileged accounts for unnecessary permissions.
- Monitor the plugin's upload paths for unexpected file types.
Detection
- Alert on new files with executable extensions (php, phtml, php5) appearing in WordPress upload directories.
- Review web server logs for POST requests to the Photo Gallery upload endpoints followed by requests to the uploaded file.
- Baseline and monitor file hashes in wp-content/uploads for unexpected additions.
- Check for low-privileged accounts performing uploads outside normal patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/130104/Photo-Gallery-1.2.5-Shell-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/130384/WordPress-Photo-Gallery-1.2.5-Unrestricted-File-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/72620 | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/130104/Photo-Gallery-1.2.5-Shell-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/130384/WordPress-Photo-Gallery-1.2.5-Unrestricted-File-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/72620 | Third Party AdvisoryVDB Entry |
Track CVE-2014-9312 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9312), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.