CVE-2026-1463Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-18); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-18: 3Mentions · 2026-03-19: 1Technical Details · 2026-03-18: 303-1803-19
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-183
Disclosure3
2026-03-191
Disclosure1
Full discourse4 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-1463 - smub - Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery - https://www.redpacketsecurity.com/cve-alert-cve-2026-1463-smub-photo-gallery-sliders-proofing-and-themes-nextgen-gallery/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1463 #smub #photo-gallery-sliders-proofing-and-themes-nextgen-gallery

    Post summary

    A CVE alert for CVE-2026-1463 impacting NextGEN Gallery is posted, pointing readers to a security advisory link for more information.

    0000088
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1463 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3… https://www.cve.org/CVERecord?id=CVE-2026-1463

    Post summary

    The note announces that NextGEN Gallery plugin up to v4.0.3 is vulnerable to Local File Inclusion, with no PoC, exploit, or active exploitation details provided.

    00000109
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1463: HIGH] WordPress NextGEN Gallery plugin up to ver. 4.0.3 contains a Local File Inclusion vulnerability via 'template' parameter in shortcodes, allowing attackers to execute arbitrary PHP code on...#cve,CVE-2026-1463,#cybersecurity https://cvefind.com/CVE-2026-1463

    Post summary

    The CVE-2026-1463 vulnerability in WordPress NextGEN Gallery plugin is disclosed, highlighting a Local File Inclusion flaw that permits arbitrary PHP code execution.

    0000047
    603 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1463 - High The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' pa... https://www.thehackerwire.com/vulnerability/CVE-2026-1463/ https://t.co/J8CGHhvi9F

    Post summary

    The text announces a high‑severity Local File Inclusion vulnerability (CVE‑2026‑1463) affecting the NextGEN Gallery WordPress plugin (v4.0.3 and earlier).

    0000035
    138 followersView on X

Explore more