CVE-2013-5962

Gallery Manager Plugin < 3.3.4 rev40279 - Unauthenticated Arbitrary File Upload and RCE via upload-images.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-5962. PoCs published by Vulnerability-Lab.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in WordPress Plugin Complete Gallery Manager 3.3.3. It allows remote attackers to upload malicious files via POST method to the upload-images.php file, leading to potential remote code execution.

Description

Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.

Exploits (1)

exploitdb WORKING POC
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/28377

This exploit demonstrates an arbitrary file upload vulnerability in WordPress Plugin Complete Gallery Manager 3.3.3. It allows remote attackers to upload malicious files via POST method to the upload-images.php file, leading to potential remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Complete Gallery Manager 3.3.3
No auth needed
Prerequisites: Access to the vulnerable upload-images.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/28377
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87172
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2013-09/0090.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/54894

Scores

EPSS 0.1477
EPSS Percentile 96.2%

Details

Status published
Products (24)
envato/complete_gallery_manager_plugin 1.0.0 rev25273
envato/complete_gallery_manager_plugin 1.0.1 rev25421
envato/complete_gallery_manager_plugin 1.0.2 rev25487
envato/complete_gallery_manager_plugin 2.0.0 rev27524
envato/complete_gallery_manager_plugin 2.0.1 rev27876
envato/complete_gallery_manager_plugin 2.0.2 rev28693
envato/complete_gallery_manager_plugin 2.0.3 rev28734
envato/complete_gallery_manager_plugin 3.0.0 rev29469
envato/complete_gallery_manager_plugin 3.0.1 rev29536
envato/complete_gallery_manager_plugin 3.1.0 rev30003
... and 14 more
Published Sep 30, 2013
Tracked Since Feb 18, 2026