CVE-2015-9538

MEDIUM

NextGEN Gallery < 2.1.15 - Path Traversal via Path Selection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-9538. PoCs published by Sathish Kumar, including Metasploit module auxiliary/scanner/http/wp_nextgen_galley_file_read.

AI-analyzed exploit summary This Metasploit module exploits an authenticated directory traversal vulnerability in WordPress NextGEN Gallery plugin version 2.1.7, allowing arbitrary directory reading with web server privileges. It requires valid WordPress credentials and leverages a nonce-based authentication mechanism.

Description

The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.

Exploits (1)

metasploit WORKING POC
by Sathish Kumar · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_nextgen_galley_file_read.rb

This Metasploit module exploits an authenticated directory traversal vulnerability in WordPress NextGEN Gallery plugin version 2.1.7, allowing arbitrary directory reading with web server privileges. It requires valid WordPress credentials and leverages a nonce-based authentication mechanism.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: WordPress NextGEN Gallery plugin version 2.1.7
Auth required
Prerequisites: Valid WordPress credentials · NextGEN Gallery plugin version 2.1.7 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://wordpress.org/plugins/nextgen-gallery/#developers
Exploit, Third Party Advisory x_refsource_misc
https://github.com/cybersecurityworks/Disclosed/issues/2
Exploit, Third Party Advisory x_refsource_misc
https://cxsecurity.com/issue/WLB-2015080165
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://www.openwall.com/lists/oss-security/2015/08/28/4
Mailing List, Third Party Advisory x_refsource_misc
https://www.openwall.com/lists/oss-security/2015/09/01/7
Exploit, Third Party Advisory x_refsource_misc
https://cybersecurityworks.com/zerodays/cve-2015-9538-nextgen.html

Scores

CVSS v3 6.5
EPSS 0.7025
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
imagely/nextgen_gallery < 2.1.15
Published Nov 26, 2019
Tracked Since Feb 18, 2026