All verified exploits

CVE-2026-1463 Local File Inclusion via Gallery Template Parameter

Deterministic high WordPress Added cve-verified-cve-2026-1463

Detects WordPress installs running NextGEN Gallery at version 4.0.3 or earlier. The LegacyTemplateLocator accepts shortcode template parameters without path validation, allowing Author-level users to include and execute arbitrary PHP files on the server via path traversal sequences. This exposes wp-config.php credentials, enables reading sensitive server files, and achieves code execution when combined with file upload capabilities.

Related WordPress exploits

Is your app exploitable through CVE-2026-1463?

Scan your domain free