← Vulnerability feed

Vulnerability record · CVE-2014-9312 · published 28 August 2017

CVE-2014-9312: WordPress Photo Gallery plugin unrestricted file upload

10web · Photo Gallery

Photo Gallery 1.2.5 (10web) contains an unrestricted file upload flaw (CWE-434) that lets a user upload files without proper type or extension validation. Because the plugin is a WordPress component, a successful upload can place executable content on the web server, making this a direct path to remote code execution. The record is thin on technical detail beyond the flaw class and version, but the impact class is severe.

8.8 CVSS 3.0 High EPSS 45% · top 1.2% CWE-434 · Unrestricted file upload
8.8CVSS 3.0 base score, v2 6.5
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 with public exploit references and very high EPSS, though no KEV listing or confirmed campaign.

What it is

Photo Gallery 1.2.5 (10web) contains an unrestricted file upload flaw (CWE-434) that lets a user upload files without proper type or extension validation. Because the plugin is a WordPress component, a successful upload can place executable content on the web server, making this a direct path to remote code execution. The record is thin on technical detail beyond the flaw class and version, but the impact class is severe.

Impact

An attacker with a low-privileged account can upload arbitrary files, including a web shell, and execute code on the host under the web server's privileges. That yields full compromise of the site's confidentiality, integrity and availability.

Attack surface

Reached over the network through the plugin's upload functionality; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). No authentication bypass is implied, so a valid low-privileged account is needed.

Exploitation

Public exploit code is referenced (Packetstorm shell upload entries) and EPSS is 0.45354 (98.7th percentile), indicating high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaign is recorded here.

What to do

  • Update or remove the Photo Gallery plugin; 1.2.5 is the only version named, so treat any unpatched install as vulnerable.
  • If patching is not immediately possible, disable the plugin or restrict upload functionality.
  • Enforce server-side upload validation and block script execution in upload directories.
  • Restrict who can upload media and review low-privileged accounts for unnecessary permissions.
  • Monitor the plugin's upload paths for unexpected file types.

Detection

  • Alert on new files with executable extensions (php, phtml, php5) appearing in WordPress upload directories.
  • Review web server logs for POST requests to the Photo Gallery upload endpoints followed by requests to the uploaded file.
  • Baseline and monitor file hashes in wp-content/uploads for unexpected additions.
  • Check for low-privileged accounts performing uploads outside normal patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9312 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-128110web photo gallery sql injection vulnerabilityThe Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, maki…EPSS 43%9.8CVE-2022-0169Photo Gallery by 10Web WordPress plugin unauthenticated SQL injectionThe Photo Gallery by 10Web WordPress plugin before 1.6.0 fails to validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a …EPSS 75%analysed9.8CVE-2021-2413910web photo gallery sql injection vulnerabilityUnvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models…EPSS 5.5%9.8CVE-2019-1611910web photo gallery sql injection vulnerabilitySQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php albu…EPSS 25%9.8CVE-2019-1431310web photo gallery sql injection vulnerabilityA SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability wou…EPSS 4.5%8.8CVE-2024-548110web photo gallery path traversal vulnerabilityThe Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including,…EPSS 0.73%8.8CVE-2015-938010web photo gallery cross-site request forgery vulnerabilityThe photo-gallery plugin before 1.2.42 for WordPress has CSRF.EPSS 0.82%7.5CVE-2015-105510web photo gallery sql injection vulnerabilitySQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_b…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2014-9312), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.